Skip to main content

Asterisk Multiple Vulnerabilities

Last Update Date: 29 Aug 2013 09:35 Release Date: 29 Aug 2013 3966 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Asterisk. A remote user can cause denial of service conditions.

  1. A remote user can send a SIP ACK with SDP that is received after the channel has been terminated to cause the target service to crash.
  2. A remote user can send a specially crafted SIP request with an invalid SDP to cause the target service to crash.

Impact

  • Denial of Service

System / Technologies affected

  • 1.8.x, 10.x, 11.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (1.8.23.1, 10.12.3, 11.5.1; 1.8.15-cert3, 11.2-cert2).

Vulnerability Identifier

  • No CVE information is available

Source


Related Link