aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authorflo <flo@FreeBSD.org>2011-06-29 18:15:17 +0800
committerflo <flo@FreeBSD.org>2011-06-29 18:15:17 +0800
commit7d14d88addbe692968e5e8e4498dbc6124ceea96 (patch)
treea8d329df2d982ae9e396d309195286387bf0cb75 /security
parent5bf582a893038c60ad3eecf91d012a6c132e07bd (diff)
downloadfreebsd-ports-gnome-7d14d88addbe692968e5e8e4498dbc6124ceea96.tar.gz
freebsd-ports-gnome-7d14d88addbe692968e5e8e4498dbc6124ceea96.tar.zst
freebsd-ports-gnome-7d14d88addbe692968e5e8e4498dbc6124ceea96.zip
document one more vulnerability in the recent asterisk entry
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml11
1 files changed, 8 insertions, 3 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index e525f2efa8c9..0617551f1b15 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -39,15 +39,15 @@ Note: Please add new entries to the beginning of this file.
<affects>
<package>
<name>asterisk14</name>
- <range><gt>1.4.*</gt><lt>1.4.41.1</lt></range>
+ <range><gt>1.4.*</gt><lt>1.4.41.2</lt></range>
</package>
<package>
<name>asterisk16</name>
- <range><gt>1.6.*</gt><lt>1.6.2.18.1</lt></range>
+ <range><gt>1.6.*</gt><lt>1.6.2.18.2</lt></range>
</package>
<package>
<name>asterisk18</name>
- <range><gt>1.8.*</gt><lt>1.8.4.3</lt></range>
+ <range><gt>1.8.*</gt><lt>1.8.4.4</lt></range>
</package>
</affects>
<description>
@@ -66,19 +66,24 @@ Note: Please add new entries to the beginning of this file.
<p>AST-2011-010: A memory address was inadvertently transmitted over
the network via IAX2 via an option control frame and the remote party
would try to access it.</p>
+ <p>Possible enumeration of SIP users due to differing authentication
+ responses.</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2011-2529</cvename>
<cvename>CVE-2011-2535</cvename>
+ <cvename>CVE-2011-2536</cvename>
<url>http://downloads.asterisk.org/pub/security/AST-2011-008.html</url>
<url>http://downloads.asterisk.org/pub/security/AST-2011-009.html</url>
<url>http://downloads.asterisk.org/pub/security/AST-2011-010.html</url>
+ <url>http://downloads.asterisk.org/pub/security/AST-2011-011.html</url>
</references>
<dates>
<discovery>2011-06-24</discovery>
<entry>2011-06-25</entry>
+ <modified>2011-06-29</modified>
</dates>
</vuln>