Asterisk remote heap overflow

Source: snapvoip.blogspot.com

Notice to all Asterisk users:
A security Advisory has been issued on Asterisk open source PBX, IPPBX. Please fix as soon as possible, any application or servers using Asterisk like TRIXBOX, should fix this overflow. I am running Asterisk 1.4-beta2 and not affected.

Asterisk - chan_skinny Remote Unauthenticated Heap Overflow

Vendor Website:
http://www.asterisk.org
Affected Version:
All 1.2-branch releases prior to and including 1.2.12.1
All 1.0-branch releases prior to and including 1.0.12

Not Affected:
All 1.4-branch beta releases (1.4.0-beta1, 1.4.0-beta2)

== Overview ==
Asterisk is "The Opensource PBX", a popular software telephony server.

The Asterisk Skinny channel driver for Cisco SCCP phones chan_skinny.so)
incorrectly validates a length value in the packet header. An integer
wrap-around leads to heap overwrite, and arbitrary remote code execution
as root.

== Details ==

The function ’static int get_input(struct skinnysession *s)’ in
chan_skinny.c incorrectly validates a user supplied length in the packet
header. In the code below, four bytes of data are read from the socket,
cast to a signed integer, and assigned to dlen. If dlen is between -1
and -8 then (dlen + 8) will integer wrap to be greater than zero, but
less than sizeof(s->inbuf) for the purposes of this comparison.

Next, dlen + 4 is passed to read() as the maximum number of bytes to
write to s->inbuf+4. Read() takes an unsigned value, so dlen is
interpreted as a very large number. For example, a value of -6 is
interpreted as 0xfffffffa bytes. This instructs read() to write beyond
the allocated 1000 byte length of the buffer s->inbuf.
== Solutions ==

- Disable the chan_skinny module if it is not required.
- Firewall port 2000/tcp from untrusted networks.
- Install the vendor supplied upgrades:
1.0-branch: Upgrade to 1.0.12 or later
1.2-branch: Upgrade to 1.2.13 or later

== Credit ==

Discovered and advised to Digium 17th October, 2006 by Adam Boileau of
Security-Assessment.com.

Published on October 20th, 2006 under , , , , , ,


Last 20 posts tagged "Trixbox"

Trixbox (CE, SE, CCE, EE)…What is Best For You?

Source: blog.voipsupply.com

In the realm of IP PBX units there are many flavors to choose from. You have the small petite servers for a few users, such as a small or home office, then branch out to the big monsters that…

Published on May 7th, 2008 under

Want To Save $40,000?

Source: asteriskblog.com

Who doesn’t? Well, if you really want to save that much, you might want to consider switching over to VOIP for your business. It has long been acknowledged that VOIP services are far mor…

Published on April 25th, 2008 under , , ,

Asterisk Appliance Roundup

Source: blog.voipsupply.com

The proliferation of open source, Asterisk-based, IP PBX software platforms has lead to demand for inexpensive, telco-grade hardware appliances. There are likely more than a dozen manufacturers…

trixbox CE 2.6 Beta Is Ready

Source: snapvoip.blogspot.com

trixbox CE 2.6 Beta is the latest version of trixbox and is ready for you to download at Sourceforge. This release comes with CentOS 5.1 as the OS and Asterisk 1.4 as the engine, trixbox CE…

Published on February 21st, 2008 under , ,

Did TRIXBOX Trick You?

Source: snapvoip.blogspot.com

I was shocked to learn that Trixbox phoned home, delivering more than the version you were using. It seem to have dumped more information based on a request to a remotely-configurable BOT, a…

Published on January 10th, 2008 under , ,

TrixBox Pro, Breaking Records and Setting a New Phase

Source: snapvoip.blogspot.com

Today I heard some good news that made me smile. Fonality has proved, once again that OSS Software is viable and people with capability could really make profit and achieve success with Open…

Published on October 22nd, 2007 under ,

Tribox 2.4 Beta Released

Source: asteriskblog.com

The latest version of Tribox 2, which is the most popular Asterisk-based telephony platform in use now, was released by Fonality last week. Tribox 2.4 is includes the latest releases of CentOS…

Published on August 13th, 2007 under , , ,

TrixBox Pro, officially out today

Source: snapvoip.blogspot.com

LOS ANGELES — August 13, 2007 — Small and medium-size businesses no longer need to pay for a phone system or in-network phone calls worldwide, according to an announcement today from Fonality,…

Published on August 13th, 2007 under , , , , , , , , , , ,

Trixbox 2.4 released with ASTERISK 1.4 on CentOS 5

Source: snapvoip.blogspot.com

Last week seems have been a very busy one. FreePBX has released a the first RC1 for FreePBX2.3 and TrixBox has released TrixBox 2.4 witch incorporates the newest releases of CentOS 5, Asterisk…

Published on August 12th, 2007 under , , , , , , , ,

ASTLinux, Trixbox, Ferrari, Prius they are not all Apples!

Source: snapvoip.blogspot.com

Update:Kristian used a Toyota Siena in his example but I used Prius as it is closer to my real life situation! I used to like high power cars but one day rented a small Prius car. Although I…

Published on July 14th, 2007 under , , , ,

TrixBox Appliance! Sold to the first ever customer!

Source: snapvoip.blogspot.com

VoIP IP Telephony @ http://snapvoip.blogspot.comThe TrixBox Appliance that is a hardware appliance designed only by Trixbox for Trixbox has been sold to it’s first customer at VON.The product…

Published on June 8th, 2007 under , , , , ,

How To Install trixbox Video

Source: blog.voipsupply.com

New Video Shows Your How to Install trixbox
Pal Kerry Garrison just pointed me to this awesome video he created that show a complete beginner how to get trixbox installed (and installed correctly)for…

Published on April 5th, 2007 under

Traditional Telcos Are Still Out To Get VoIP Companies

Source: asteriskblog.com

VoIP is getting more popular with business and home users. But while business users have the funds and manpower to set up and maintain their own gateways and VoIP equipment (such as with self-installed…

Published on March 28th, 2007 under , , , ,

AsteriskNOW, coming out in full force.

Source: snapvoip.blogspot.com

VoIP IP Telephony @ http://snapvoip.blogspot.comThe VON 2007 was a blast. Among many other things that I spent my two days at VON, I noticed very well how AsteriskNOW is coming out in full forc…

Published on March 24th, 2007 under , , , , , , ,

Fonality Launches trixbox Appliance

Source: asteriskblog.com

Fonality has recently announced the launch of the Asterisk-based trixbox Appliance. The Appliance is meant to be an enterprise-grade solution, based on the open-source Asterisk, which is also…

Published on March 19th, 2007 under ,

Cisco Lets Apple Use “iPhone” Name

Source: asteriskblog.com

When Apple’s Steve Jobs announced the iPhone during the Macworld Expo last January, this shocked the whole tech community. It wasn’t so much the announcement of an Apple mobile phone that…

Published on February 26th, 2007 under , , ,

Fonality Secures $7 Million Investment From Intel

Source: asteriskblog.com

Fonality, creator of the Asterisk-bsed trixbox telephony system and the business-oriented PBXtra, has recently secured $7 million in funding from Intel’s investment arm, Intel Capital.

Fonality®,…

Published on February 14th, 2007 under ,

WorxBox an independent TrixBox?

Source: snapvoip.blogspot.com

VoIP IP Telephony @ http://snapvoip.blogspot.comI was reading Sinologic article that lead me to this discovery. It seems that the TrixBox replacement have come to the open source arena. The AsteriskNow,…

Published on February 13th, 2007 under , , ,

Trixbox 2.0 in CentOS VE, Virtual Environment

Source: snapvoip.blogspot.com

VoIP IP Telphony @ snapvoip.blogspot.comI wrote about OpenVZ on the gridtech blog; Link is below,It is a virtual environment for Linux, like vmware or Xen. But today I noticed that their is an…

Published on February 12th, 2007 under , , ,

Fonality Announces trixbox Certification Program

Source: asteriskblog.com

Fonality, creator of the popular trixbox Asterisk-based telephony system, has announced that it will run Fonality trixbox Open Communications Certification workshops for professionals involved…

Published on February 7th, 2007 under ,
Member of "Hype Media! Network"