Asterisk SIP Invite Message Remote Denial of Service Vulnerability
BID:23031
Info
Asterisk SIP Invite Message Remote Denial of Service Vulnerability
| Bugtraq ID: | 23031 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-1561 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2007 12:00AM |
| Updated: | Aug 28 2007 11:02PM |
| Credit: | Humberto J. Abdelnur is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE Linux 10.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Asterisk Asterisk 1.4.1 Asterisk Asterisk 1.2.16 Asterisk Asterisk 1.2.15 Asterisk Asterisk 1.2.14 |
| Not Vulnerable: |
Asterisk Asterisk 1.4.2 Asterisk Asterisk 1.2.17 |
Discussion
Asterisk SIP Invite Message Remote Denial of Service Vulnerability
Asterisk is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to cause the application to crash, effectively denying service to legitimate users.
Asterisk is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to cause the application to crash, effectively denying service to legitimate users.
Exploit / POC
Asterisk SIP Invite Message Remote Denial of Service Vulnerability
To exploit this issue, attackers may use readily available network utilities.
The following proof of concept is available.
To exploit this issue, attackers may use readily available network utilities.
The following proof of concept is available.
Solution / Fix
Asterisk SIP Invite Message Remote Denial of Service Vulnerability
Solution:
Asterisk 1.2.17 and 1.4.2 have been released to address this issue; please contact the vendor for information on how to obtain fixes and upgrades.
Asterisk Asterisk 1.2.14
Asterisk Asterisk 1.2.15
Asterisk Asterisk 1.2.16
Asterisk Asterisk 1.4.1
Solution:
Asterisk 1.2.17 and 1.4.2 have been released to address this issue; please contact the vendor for information on how to obtain fixes and upgrades.
Asterisk Asterisk 1.2.14
-
Asterisk asterisk-1.2.17.tar.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.17.tar.gz
Asterisk Asterisk 1.2.15
-
Asterisk asterisk-1.2.17.tar.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.17.tar.gz
Asterisk Asterisk 1.2.16
-
Asterisk asterisk-1.2.17.tar.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.17.tar.gz
Asterisk Asterisk 1.4.1
-
Asterisk asterisk-1.4.2.tar.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.4.2.tar.gz
References
Asterisk SIP Invite Message Remote Denial of Service Vulnerability
References:
References:
- Asterisk 1.2.17 released (Asterisk)
- Asterisk 1.4.2 released (Asterisk)
- Asterisk@Home Homepage (Asterisk@Home)