漏洞信息详情
Sangoma Technologies Asterisk 安全漏洞
漏洞简介
Sangoma Technologies Asterisk是加拿大Sangoma Technologies公司的一套开源电话交换机(PBX)系统软件。该软件支持语音信箱、多方语音会议、交互式语音应答(IVR)等。
Sangoma Asterisk 中存在安全漏洞。该漏洞源于允许未经身份验证的远程攻击者通过重播SRTP数据包提前终止安全调用。以下产品及版本受到影响:Sangoma Asterisk 13.38.1, Sangoma Asterisk 16.16.0, Sangoma Asterisk 17.9.1, Sangoma Asterisk 18.2.0, Certified Asterisk 16.8-cert5。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://issues.asterisk.org/jira/browse/ASTERISK-29260
参考网址
来源:MISC
链接:https://downloads.asterisk.org/pub/security/
来源:MISC
链接:https://packetstormsecurity.com/files/161473/Asterisk-Project-Security-Advisory-AST-2021-003.html
来源:CONFIRM
链接:https://downloads.asterisk.org/pub/security/AST-2021-003.html
来源:CONFIRM
链接:https://issues.asterisk.org/jira/browse/ASTERISK-29260
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/Feb/59
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161473/Asterisk-Project-Security-Advisory-AST-2021-003.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-26712
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Asterisk-denial-of-service-via-SRTP-Calls-34616
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0624
受影响实体
暂无
补丁
- Sangoma Technologies Asterisk 安全漏洞的修复措施<!--2021-2-18-->
还没有评论,来说两句吧...