Skip to main content

Asterisk UPDTL Buffer Overflow Vulnerabilities

Last Update Date: 23 Feb 2011 15:24 Release Date: 23 Feb 2011 6398 Views

RISK: High Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

 

Multiple vulnerabilities have been identified in Asterisk, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. These issues are caused by stack and heap overflow errors in the UDPTL decoding routines, which could be exploited by remote attackers to crash an affected application or compromise a vulnerable system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Asterisk Open Source versions 1.4.x
  • Asterisk Open Source versions 1.6.x
  • Asterisk Business Edition versions C.x.x
  • AsteriskNOW versions 1.5
  • s800i (Asterisk Appliance) versions 1.2.x

Solutions

 
Before installation of the software, please visit the software manufacturer web-site for more details.
  • Asterisk Open Source - Upgrade to version 1.4.39.2, 1.6.1.22, 1.6.2.16.2, or 1.8.2.4.
  • Asterisk Business Edition - Upgrade to version C.3.6.3

Vulnerability Identifier

  • No CVE information is available

Source


Related Link