Asterisk & IAX Client Library Buffer Overflow Advisories
June 13th, 2006 by Dustin D. TrammellCore Security released two advisories on the 9th (1, 2) covering buffer overflow vulnerabilities related to short UDP packets in two vulnerable applications, the Asterisk Open Source IPBX, and applications making use of the IAX client library which provides an IAX/IAX2 protocol stack for 3rd party applications. Both vulnerabilities center around the IAX2 protocol and truncated UDP frames.
A press release from yesterday which summarizes the advisories from Core can be found here.
Updated software releases and/or patches have been released, which are the same patches that David Endler posted about earlier this week.
