Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Service Vulnerability
BID:25392
Info
Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Service Vulnerability
| Bugtraq ID: | 25392 |
| Class: | Design Error |
| CVE: |
CVE-2007-4455 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2007 12:00AM |
| Updated: | Aug 31 2007 01:22AM |
| Credit: | Jon Moldenauer is credited with the discovery of this vulnerability. |
| Vulnerable: |
Asterisk s800i Appliance 1.0.2 Asterisk s800i Appliance 1.0.1 Asterisk s800i Appliance 1.0 Asterisk AsteriskNow Beta 6 Asterisk AsteriskNow Beta 5 Asterisk Asterisk Appliance Developer Kit 0.7 Asterisk Asterisk Appliance Developer Kit 0.6 Asterisk Asterisk Appliance Developer Kit 0.5 Asterisk Asterisk Appliance Developer Kit 0.4 Asterisk Asterisk Appliance Developer Kit 0.3 Asterisk Asterisk Appliance Developer Kit 0.2 Asterisk Asterisk 1.4.10 Asterisk Asterisk 1.4.9 Asterisk Asterisk 1.4.8 Asterisk Asterisk 1.4.7 Asterisk Asterisk 1.4.4 Asterisk Asterisk 1.4.3 Asterisk Asterisk 1.4.2 Asterisk Asterisk 1.4.1 Asterisk Asterisk 1.4 Beta |
| Not Vulnerable: |
Asterisk s800i Appliance 1.0.3 Asterisk AsteriskNow Beta 7 Asterisk Asterisk Appliance Developer Kit 0.8 Asterisk Asterisk 1.4.11 |
Discussion
Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Service Vulnerability
Asterisk is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to consume all system resources, denying service to legitimate users.
Asterisk is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to consume all system resources, denying service to legitimate users.
Exploit / POC
Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Service Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Asterisk Asterisk Appliance Developer Kit 0.2
Asterisk Asterisk Appliance Developer Kit 0.3
Asterisk Asterisk Appliance Developer Kit 0.4
Asterisk Asterisk Appliance Developer Kit 0.5
Asterisk Asterisk Appliance Developer Kit 0.6
Asterisk Asterisk Appliance Developer Kit 0.7
Asterisk Asterisk 1.4.1
Asterisk Asterisk 1.4.10
Asterisk Asterisk 1.4.2
Asterisk Asterisk 1.4.3
Asterisk Asterisk 1.4.4
Asterisk Asterisk 1.4.7
Asterisk Asterisk 1.4.8
Asterisk Asterisk 1.4.9
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Asterisk Asterisk Appliance Developer Kit 0.2
-
Asterisk Asterisk_Appliance_Developer_Kit_0.8.0
http://downloads.digium.com/pub/telephony/aadk/current
Asterisk Asterisk Appliance Developer Kit 0.3
-
Asterisk Asterisk_Appliance_Developer_Kit_0.8.0
http://downloads.digium.com/pub/telephony/aadk/current
Asterisk Asterisk Appliance Developer Kit 0.4
-
Asterisk Asterisk_Appliance_Developer_Kit_0.8.0
http://downloads.digium.com/pub/telephony/aadk/current
Asterisk Asterisk Appliance Developer Kit 0.5
-
Asterisk Asterisk_Appliance_Developer_Kit_0.8.0
http://downloads.digium.com/pub/telephony/aadk/current
Asterisk Asterisk Appliance Developer Kit 0.6
-
Asterisk Asterisk_Appliance_Developer_Kit_0.8.0
http://downloads.digium.com/pub/telephony/aadk/current
Asterisk Asterisk Appliance Developer Kit 0.7
-
Asterisk Asterisk_Appliance_Developer_Kit_0.8.0
http://downloads.digium.com/pub/telephony/aadk/current
Asterisk Asterisk 1.4.1
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.10
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.2
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.3
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.4
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.7
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.8
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
Asterisk Asterisk 1.4.9
-
Asterisk asterisk-1.4-current.tar.gz
http://downloads.digium.com/pub/telephony/asterisk/asterisk-1.4-curren t.tar.gz
References
Asterisk SIP Dialog History Resource Exhaustion Remote Denial of Service Vulnerability
References:
References: