{"id":"MGASA-2014-0172","summary":"Updated asterisk packages fix security vulnerabilities","details":"Updated asterisk packages fix security vulnerabilities:\n\nIn Asterisk before 11.8.1, sending a HTTP request that is handled by Asterisk\nwith a large number of Cookie headers could overflow the stack. You could\neven exhaust memory if you sent an unlimited number of headers in the request\n(CVE-2014-2286).\n\nIn Asterisk before 11.8.1, an attacker can use all available file descriptors\nusing SIP INVITE requests. Each INVITE meeting certain conditions will leak a\nchannel and several file descriptors. The file descriptors cannot be released\nwithout restarting Asterisk which may allow intrusion detection systems to be\nbypassed by sending the requests slowly (CVE-2014-2287).\n","modified":"2026-04-16T06:25:31.447383715Z","published":"2014-04-15T18:22:45Z","upstream":["CVE-2014-2286","CVE-2014-2287"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0172.html"},{"type":"WEB","url":"http://downloads.asterisk.org/pub/security/AST-2014-001.html"},{"type":"WEB","url":"http://downloads.asterisk.org/pub/security/AST-2014-002.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13061"}],"affected":[{"package":{"name":"asterisk","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/asterisk?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.8.1-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0172.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}