Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-5977

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-5977
Last Modified 02 Feb 2013 12:10:31
Published 04 Jan 2013 10:55:02
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-5977

Summary

Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.

Vulnerable Systems

Application

  • Digium Asterisk 1.8.0

  • Digium Asterisk 1.8.1

  • Digium Asterisk 1.8.1.1

  • Digium Asterisk 1.8.1.2

  • Digium Asterisk 1.8.10.0

  • Digium Asterisk 1.8.10.1

  • Digium Asterisk 1.8.11.0

  • Digium Asterisk 1.8.11.1

  • Digium Asterisk 1.8.12

  • Digium Asterisk 1.8.12.0

  • Digium Asterisk 1.8.13.0

  • Digium Asterisk 1.8.13.1

  • Digium Asterisk 1.8.14.0

  • Digium Asterisk 1.8.14.1

  • Digium Asterisk 1.8.15.0

  • Digium Asterisk 1.8.15.1

  • Digium Asterisk 1.8.16.0

  • Digium Asterisk 1.8.17.0

  • Digium Asterisk 1.8.18.0

  • Digium Asterisk 1.8.18.1

  • Digium Asterisk 1.8.19.0

  • Digium Asterisk 1.8.2

  • Digium Asterisk 1.8.2.1

  • Digium Asterisk 1.8.2.2

  • Digium Asterisk 1.8.2.3

  • Digium Asterisk 1.8.2.4

  • Digium Asterisk 1.8.3

  • Digium Asterisk 1.8.3.1

  • Digium Asterisk 1.8.3.2

  • Digium Asterisk 1.8.3.3

  • Digium Asterisk 1.8.4

  • Digium Asterisk 1.8.4.1

  • Digium Asterisk 1.8.4.2

  • Digium Asterisk 1.8.4.3

  • Digium Asterisk 1.8.4.4

  • Digium Asterisk 1.8.5

  • Digium Asterisk 1.8.5.0

  • Digium Asterisk 1.8.6.0

  • Digium Asterisk 1.8.7.0

  • Digium Asterisk 1.8.7.1

  • Digium Asterisk 1.8.8.0

  • Digium Asterisk 1.8.8.1

  • Digium Asterisk 1.8.8.2

  • Digium Asterisk 1.8.9.0

  • Digium Asterisk 1.8.9.1

  • Digium Asterisk 1.8.9.2

  • Digium Asterisk 1.8.9.3

  • Digium Asterisk 10.0.0

  • Digium Asterisk 10.0.1

  • Digium Asterisk 10.1.0

  • Digium Asterisk 10.1.1

  • Digium Asterisk 10.1.2

  • Digium Asterisk 10.1.3

  • Digium Asterisk 10.10.0

  • Digium Asterisk 10.10.1

  • Digium Asterisk 10.11.0

  • Digium Asterisk 10.2.0

  • Digium Asterisk 10.2.1

  • Digium Asterisk 10.3.0

  • Digium Asterisk 10.3.1

  • Digium Asterisk 10.4.0

  • Digium Asterisk 10.4.1

  • Digium Asterisk 10.4.2

  • Digium Asterisk 10.5.0

  • Digium Asterisk 10.5.1

  • Digium Asterisk 10.5.2

  • Digium Asterisk 10.6.0

  • Digium Asterisk 10.6.1

  • Digium Asterisk 10.7.0

  • Digium Asterisk 10.7.1

  • Digium Asterisk 10.8.0

  • Digium Asterisk 10.9.0

  • Digium Asterisk 11.0.0

  • Digium Asterisk 11.0.1

  • Digium Asterisk 11.0.2

  • Digium Asterisk 11.1.0

  • Digium Asterisk 11.1.1

  • Digium Certified Asterisk 1.8.11


References

CONFIRM - https://issues.asterisk.org/jira/browse/ASTERISK-20175

CONFIRM - http://downloads.asterisk.org/pub/security/AST-2012-015

DEBIAN - DSA-2605


Last Updated: 27 May 2016 11:01:34