Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-5976

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2012-5976
Last Modified 02 Feb 2013 12:10:31
Published 04 Jan 2013 06:52:14
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-5976

Summary

Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers to cause a denial of service (daemon crash) via TCP data using the (1) SIP, (2) HTTP, or (3) XMPP protocol.

Vulnerable Systems

Application

  • Digium Asterisk 1.8.0

  • Digium Asterisk 1.8.1

  • Digium Asterisk 1.8.1.1

  • Digium Asterisk 1.8.1.2

  • Digium Asterisk 1.8.10.0

  • Digium Asterisk 1.8.10.1

  • Digium Asterisk 1.8.11.0

  • Digium Asterisk 1.8.11.1

  • Digium Asterisk 1.8.12

  • Digium Asterisk 1.8.12.0

  • Digium Asterisk 1.8.13.0

  • Digium Asterisk 1.8.13.1

  • Digium Asterisk 1.8.14.0

  • Digium Asterisk 1.8.14.1

  • Digium Asterisk 1.8.15.0

  • Digium Asterisk 1.8.15.1

  • Digium Asterisk 1.8.16.0

  • Digium Asterisk 1.8.17.0

  • Digium Asterisk 1.8.18.0

  • Digium Asterisk 1.8.18.1

  • Digium Asterisk 1.8.19.0

  • Digium Asterisk 1.8.2

  • Digium Asterisk 1.8.2.1

  • Digium Asterisk 1.8.2.2

  • Digium Asterisk 1.8.2.3

  • Digium Asterisk 1.8.2.4

  • Digium Asterisk 1.8.3

  • Digium Asterisk 1.8.3.1

  • Digium Asterisk 1.8.3.2

  • Digium Asterisk 1.8.3.3

  • Digium Asterisk 1.8.4

  • Digium Asterisk 1.8.4.1

  • Digium Asterisk 1.8.4.2

  • Digium Asterisk 1.8.4.3

  • Digium Asterisk 1.8.4.4

  • Digium Asterisk 1.8.5

  • Digium Asterisk 1.8.5.0

  • Digium Asterisk 1.8.6.0

  • Digium Asterisk 1.8.7.0

  • Digium Asterisk 1.8.7.1

  • Digium Asterisk 1.8.8.0

  • Digium Asterisk 1.8.8.1

  • Digium Asterisk 1.8.8.2

  • Digium Asterisk 1.8.9.0

  • Digium Asterisk 1.8.9.1

  • Digium Asterisk 1.8.9.2

  • Digium Asterisk 1.8.9.3

  • Digium Asterisk 10.0.0

  • Digium Asterisk 10.0.1

  • Digium Asterisk 10.1.0

  • Digium Asterisk 10.1.1

  • Digium Asterisk 10.1.2

  • Digium Asterisk 10.1.3

  • Digium Asterisk 10.10.0

  • Digium Asterisk 10.10.1

  • Digium Asterisk 10.11.0

  • Digium Asterisk 10.2.0

  • Digium Asterisk 10.2.1

  • Digium Asterisk 10.3.0

  • Digium Asterisk 10.3.1

  • Digium Asterisk 10.4.0

  • Digium Asterisk 10.4.1

  • Digium Asterisk 10.4.2

  • Digium Asterisk 10.5.0

  • Digium Asterisk 10.5.1

  • Digium Asterisk 10.5.2

  • Digium Asterisk 10.6.0

  • Digium Asterisk 10.6.1

  • Digium Asterisk 10.7.0

  • Digium Asterisk 10.7.1

  • Digium Asterisk 10.8.0

  • Digium Asterisk 10.9.0

  • Digium Asterisk 11.0.0

  • Digium Asterisk 11.0.1

  • Digium Asterisk 11.0.2

  • Digium Asterisk 11.1.0

  • Digium Asterisk 11.1.1

  • Digium Certified Asterisk 1.8.11


References

CONFIRM - http://downloads.asterisk.org/pub/security/AST-2012-014

DEBIAN - DSA-2605


Last Updated: 27 May 2016 11:01:33