Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2216

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2011-2216
Last Modified 06 Sep 2011 11:17:10
Published 06 Jun 2011 03:55:03
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-2216

Summary

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.

Vulnerable Systems

Application

  • Digium Asterisk 1.8.0

  • Digium Asterisk 1.8.1

  • Digium Asterisk 1.8.1.1

  • Digium Asterisk 1.8.1.2

  • Digium Asterisk 1.8.2

  • Digium Asterisk 1.8.2.1

  • Digium Asterisk 1.8.2.2

  • Digium Asterisk 1.8.2.3

  • Digium Asterisk 1.8.2.4

  • Digium Asterisk 1.8.3

  • Digium Asterisk 1.8.3.1

  • Digium Asterisk 1.8.3.2

  • Digium Asterisk 1.8.3.3

  • Digium Asterisk 1.8.4

  • Digium Asterisk 1.8.4.1


References

XF - asterisk-parseurifull-dos(67812)

BID - 48096

BUGTRAQ - 20110602 AST-2011-007

SECTRACK - 1025598

SECUNIA - 44828

OSVDB - 72752

FEDORA - FEDORA-2011-8319

FEDORA - FEDORA-2011-8983

CONFIRM - http://downloads.digium.com/pub/security/AST-2011-007.html


Last Updated: 27 May 2016 10:56:57