On 09/18/2012 11:40 PM, Michael Kozma wrote:
> Le 18/09/2012 19:18, Moritz
Muehlenhoff a écrit :
-------------------------------------------------------------------------
Debian Security Advisory DSA-2550-1
security@debian.org
http://www.debian.org/security/ Moritz
Muehlenhoff
September 18, 2012
http://www.debian.org/security/faq
-------------------------------------------------------------------------
Package : asterisk
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2186 CVE-2012-3812 CVE-2012-3863
CVE-2012-4737
Several vulnerabilities were discovered in Asterisk, a PBX and
telephony
toolkit, allowing privilege escalation in the Asterisk Manager,
denial of
service or privilege escalation.
More detailed information can be found in the Asterisk advisories:
http://downloads.asterisk.org/pub/security/AST-2012-010.html
http://downloads.asterisk.org/pub/security/AST-2012-011.html
http://downloads.asterisk.org/pub/security/AST-2012-012.html
http://downloads.asterisk.org/pub/security/AST-2012-013.html
For the stable distribution (squeeze), these problems have been
fixed in
version 1:1.6.2.9-2+squeeze7.
For the testing distribution (wheezy) and the unstable
distribution (sid),
these problems have been fixed in version 1:1.8.13.1~dfsg-1.
We recommend that you upgrade your asterisk packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
>>
>>
>
> Hello,
>
> I have an error with my sip config since i have updated the
asterisk package :
>
> monitoring*CLI> module load sip
> Unable to load module sip
> Command 'module load sip' failed.
> [Sep 18 23:31:39] WARNING[7931]: loader.c:393
load_dynamic_module: Error loading module 'sip':
/usr/lib/asterisk/modules/sip.so: cannot open shared object file:
No such file or directory
> [Sep 18 23:31:39] WARNING[7931]: loader.c:801 load_resource:
Module 'sip' could not be loaded.
>
I had a similar issue after this update, but not exactly.
[Sep 19 08:41:32] WARNING[8405] loader.c: Error loading module
'chan_sip.so': /usr/lib/asterisk/modules/chan_sip.so: undefined
symbol: sip_pvt_lock_full
[Sep 19 08:41:32] WARNING[8405] loader.c: Module 'chan_sip.so' could
not be loaded.
I've installed the previous version as a quick-fix, but something
seems to have gone wrong in the build.
dpkg -i
/var/cache/apt/archives/asterisk_1%3a1.6.2.9-2+squeeze6_i386.deb
/var/cache/apt/archives/asterisk-config_1%3a1.6.2.9-2+squeeze6_all.deb
/var/cache/apt/archives/asterisk-sounds-main_1%3a1.6.2.9-2+squeeze6_all.deb
--
Met vriendelijke groet / Regards,
Herman van Rink
Initfour websolutions
|