<div dir="ltr">PSC<br><br><div class="gmail_quote">---------- Forwarded message ----------<br>From: <b class="gmail_sendername">Asterisk Security Team</b> <span dir="ltr"><<a href="mailto:security@asterisk.org">security@asterisk.org</a>></span><br>
Date: 2013/12/16<br>Subject: [asterisk-dev] AST-2013-006: Buffer Overflow when receiving odd length 16 bit SMS message<br>To: <a href="mailto:asterisk-dev@lists.digium.com">asterisk-dev@lists.digium.com</a><br><br><br> Asterisk Project Security Advisory - AST-2013-006<br>
<br>
Product Asterisk<br>
Summary Buffer Overflow when receiving odd length 16 bit SMS<br>
message<br>
Nature of Advisory Buffer Overflow and Remote Crash<br>
Susceptibility Remote SMS Messages<br>
Severity Major<br>
Exploits Known None<br>
Reported On September 26, 2013<br>
Reported By Jan Juergens<br>
Posted On December 16, 2013<br>
Last Updated On December 16, 2013<br>
Advisory Contact Scott Griepentrog <sgriepentrog AT digium DOT com><br>
CVE Name Pending<br>
<br>
Description A 16 bit SMS message that contains an odd message length<br>
value will cause the message decoding loop to run forever.<br>
The message buffer is not on the stack but will be<br>
overflowed resulting in corrupted memory and an immediate<br>
crash.<br>
<br>
Resolution This patch corrects the evaluation of the message length<br>
indicator, ensuring that the message decoding loop will stop<br>
at the end of the received message.<br>
<br>
Thanks to Jan Juergens for finding, reporting, testing, and<br>
providing a fix for this problem.<br>
<br>
Affected Versions<br>
Product Release Series<br>
Asterisk Open Source 1.8.x All Versions<br>
Asterisk Open Source 10.x All Versions<br>
Asterisk with Digiumphones 10.x-digiumphones All Versions<br>
Asterisk Open Source 11.x All Versions<br>
Certified Asterisk 1.8.x All Versions<br>
Certified Asterisk 11.x All Versions<br>
<br>
Corrected In<br>
Product Release<br>
Asterisk Open Source 1.8.24.1, 10.12.4, 11.6.1<br>
Asterisk with Digiumphones 10.12.4-digiumphones<br>
Certified Asterisk 1.8.15-cert4, 11.2-cert3<br>
<br>
Patches<br>
SVN URL Revision<br>
<a href="http://downloads.asterisk.org/pub/security/AST-2013-006-1.8.diff" target="_blank">http://downloads.asterisk.org/pub/security/AST-2013-006-1.8.diff</a> Asterisk 1.8<br>
<a href="http://downloads.asterisk.org/pub/security/AST-2013-006-10.diff" target="_blank">http://downloads.asterisk.org/pub/security/AST-2013-006-10.diff</a> Asterisk 10<br>
<a href="http://downloads.asterisk.org/pub/security/AST-2013-006-10-digiumphones.diff" target="_blank">http://downloads.asterisk.org/pub/security/AST-2013-006-10-digiumphones.diff</a> Asterisk<br>
10-digiumphones<br>
<a href="http://downloads.asterisk.org/pub/security/AST-2013-006-11.diff" target="_blank">http://downloads.asterisk.org/pub/security/AST-2013-006-11.diff</a> Asterisk 11<br>
<a href="http://downloads.asterisk.org/pub/security/AST-2013-006-1.8.15.diff" target="_blank">http://downloads.asterisk.org/pub/security/AST-2013-006-1.8.15.diff</a> Certified<br>
Asterisk 1.8.15<br>
<a href="http://downloads.asterisk.org/pub/security/AST-2013-006-11.2.diff" target="_blank">http://downloads.asterisk.org/pub/security/AST-2013-006-11.2.diff</a> Certified<br>
Asterisk 11.2<br>
<br>
Links <a href="https://issues.asterisk.org/jira/browse/ASTERISK-22590" target="_blank">https://issues.asterisk.org/jira/browse/ASTERISK-22590</a><br>
<br>
Asterisk Project Security Advisories are posted at<br>
<a href="http://www.asterisk.org/security" target="_blank">http://www.asterisk.org/security</a><br>
<br>
This document may be superseded by later versions; if so, the latest<br>
version will be posted at<br>
<a href="http://downloads.digium.com/pub/security/AST-2013-006.pdf" target="_blank">http://downloads.digium.com/pub/security/AST-2013-006.pdf</a> and<br>
<a href="http://downloads.digium.com/pub/security/AST-2013-006.html" target="_blank">http://downloads.digium.com/pub/security/AST-2013-006.html</a><br>
<br>
Revision History<br>
Date Editor Revisions Made<br>
12/16/2013 Scott Griepentrog Initial Revision<br>
<br>
Asterisk Project Security Advisory - AST-2013-006<br>
Copyright (c) 2013 Digium, Inc. All Rights Reserved.<br>
Permission is hereby granted to distribute and publish this advisory in its<br>
original, unaltered form.<br>
<span class="HOEnZb"><font color="#888888"><br>
<br>
--<br>
_____________________________________________________________________<br>
-- Bandwidth and Colocation Provided by <a href="http://www.api-digital.com" target="_blank">http://www.api-digital.com</a> --<br>
<br>
asterisk-dev mailing list<br>
To UNSUBSCRIBE or update options visit:<br>
<a href="http://lists.digium.com/mailman/listinfo/asterisk-dev" target="_blank">http://lists.digium.com/mailman/listinfo/asterisk-dev</a><br>
</font></span></div><br><br clear="all"><div><br></div>-- <br><span style="font-family:trebuchet ms,sans-serif">Sylvio Jollenbeck<br><font size="1"><a href="http://www.hosannatecnologia.com.br/" target="_blank">www.hosannatecnologia.com.br</a></font></span><br>
<img src="http://www.hosannatecnologia.com.br/pixel.fw.png"><br>
</div>