Asterisk Chan_Sip.c Unspecified Remote Denial of Service Vulnerability
BID:20835
Info
Asterisk Chan_Sip.c Unspecified Remote Denial of Service Vulnerability
| Bugtraq ID: | 20835 |
| Class: | Unknown |
| CVE: |
CVE-2006-5445 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2006 12:00AM |
| Updated: | Mar 06 2007 08:15PM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.1 Gentoo Linux Asterisk Asterisk 1.2.11 Asterisk Asterisk 1.2.11 Asterisk Asterisk 1.2.10 Asterisk Asterisk 1.2.9 Asterisk Asterisk 1.2.8 Asterisk Asterisk 1.2.7 Asterisk Asterisk 1.2.6 Asterisk Asterisk 1.2 .0-beta2 Asterisk Asterisk 1.2 .0-beta1 Asterisk Asterisk 1.0.12 Asterisk Asterisk 1.0.11 Asterisk Asterisk 1.0.10 Asterisk Asterisk 1.0.9 Asterisk Asterisk 1.0.8 Asterisk Asterisk 1.0.7 Asterisk Asterisk 1.0 Asterisk Asterisk 0.9 .0 Asterisk Asterisk 0.7.2 Asterisk Asterisk 0.7.1 Asterisk Asterisk 0.7 .0 Asterisk Asterisk 0.4 Asterisk Asterisk 0.3 Asterisk Asterisk 0.2 Asterisk Asterisk 0.1.9 -1 Asterisk Asterisk 0.1.9 Asterisk Asterisk 0.1.8 Asterisk Asterisk 0.1.7 |
| Not Vulnerable: |
Asterisk Asterisk 1.2.13 Asterisk Asterisk 1.4 Beta |
Discussion
Asterisk Chan_Sip.c Unspecified Remote Denial of Service Vulnerability
Asterisk is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to consume excessive system resources until the software becomes unresponsive to further calls, effectively denying service to legitimate users.
Asterisk versions prior to 1.2.13 and to 1.4.0-beta3 are vulnerable to this issue.
Asterisk is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to consume excessive system resources until the software becomes unresponsive to further calls, effectively denying service to legitimate users.
Asterisk versions prior to 1.2.13 and to 1.4.0-beta3 are vulnerable to this issue.
Exploit / POC
Asterisk Chan_Sip.c Unspecified Remote Denial of Service Vulnerability
To exploit this issue, attackers may use readily available network utilities.
To exploit this issue, attackers may use readily available network utilities.
Solution / Fix
Asterisk Chan_Sip.c Unspecified Remote Denial of Service Vulnerability
Solution:
Asterisk 1.2.13 and 1.4.0-beta3 have been released to address this issue. Please see the references for more information.
Asterisk Asterisk 1.0.9
Solution:
Asterisk 1.2.13 and 1.4.0-beta3 have been released to address this issue. Please see the references for more information.
Asterisk Asterisk 1.0.9
-
SuSE asterisk-1.0.9-4.6.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/asterisk-1.0.9-4 .6.i586.rpm -
SuSE asterisk-1.0.9-4.6.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/asterisk-1.0.9-4. 6.ppc.rpm -
SuSE asterisk-1.0.9-4.6.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/asterisk-1.0.9 -4.6.x86_64.rpm
References
Asterisk Chan_Sip.c Unspecified Remote Denial of Service Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- ASTEROID SIP Denial of Service Tool (Asteroid)
- Asterisk ChangeLog-1.2.13 (Digium)