Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4063

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2011-4063
Last Modified 13 Feb 2012 11:09:39
Published 21 Oct 2011 06:55:03
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2011-4063

Summary

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authenticated users to cause a denial of service (daemon crash) via a malformed request.

Vulnerable Systems

Application

  • Asterisk Open Source 1.8.7

  • Asterisk Open Source 10.0.0


References

XF - asterisk-sip-channel-driver-dos(70706)

SECTRACK - 1026191

BID - 50177

BUGTRAQ - 20111017 AST-2011-012: Remote crash vulnerability in SIP channel driver

SECUNIA - 46420

CONFIRM - http://downloads.digium.com/pub/security/AST-2011-012.html

SREASON - 8478


Last Updated: 27 May 2016 10:58:15