USN-4814-1: Asterisk vulnerabilities

Publication date

15 March 2021

Overview

Asterisk could be made to crash or run programs if it received specially crafted input.

Releases


Packages

  • asterisk - Open Source Private Branch Exchange (PBX)

Details

Richard Mudgett discovered that Asterisk did not properly check the length
of input string when setting the user field for PartyB on a CDR. A remote
attacker could use this vulnerability to cause a denial of service (crash)
or potentially execute arbitrary code. (CVE-2017-16671)

Alex Villacis Lasso discovered that Asterisk did not properly check the
length of input string when setting the user field for PartyA on a CDR. A
remote attacker could use this vulnerability to cause a denial of service
(crash) or potentially execute arbitrary code. (CVE-2017-7617)

Richard Mudgett discovered that Asterisk did not properly check the length
of input string when setting the user field for PartyB on a CDR. A remote
attacker could use this vulnerability to cause a denial of service (crash)
or potentially execute arbitrary code. (CVE-2017-16671)

Alex Villacis Lasso discovered that Asterisk did not properly check the
length of input string when setting the user field for PartyA on a CDR. A
remote attacker could use this vulnerability to cause a denial of service
(crash) or potentially execute arbitrary code. (CVE-2017-7617)

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
16.04 xenial asterisk-ooh323 –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-vpb –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-config –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-voicemail-imapstorage –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-dahdi –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-mp3 –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-voicemail –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-mobile –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-mysql –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-modules –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  
asterisk-voicemail-odbcstorage –  1:13.1.0~dfsg-1.1ubuntu4.1+esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›