Asterisk-addons 'OOH323' Channel Driver Remote Denial of Service Vulnerability
BID:29567
Info
Asterisk-addons 'OOH323' Channel Driver Remote Denial of Service Vulnerability
| Bugtraq ID: | 29567 |
| Class: | Design Error |
| CVE: |
CVE-2008-2543 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 06 2008 11:12PM |
| Credit: | Mark Michelson |
| Vulnerable: |
Asterisk Asterisk-addons 1.4.6 Asterisk Asterisk-addons 1.4.4 Asterisk Asterisk-addons 1.4.3 Asterisk Asterisk-addons 1.2.8 Asterisk Asterisk-addons 1.2.7 |
| Not Vulnerable: |
Asterisk Asterisk-addons 1.4.7 Asterisk Asterisk-addons 1.2.9 |
Discussion
Asterisk-addons 'OOH323' Channel Driver Remote Denial of Service Vulnerability
Asterisk-addons is prone to a remote denial-of-service vulnerability that stems from a design error.
Successful exploits can crash the 'OOH323' channel driver of Asterisk-addons, causing denial-of-service conditions for legitimate users.
The vulnerability affects the following:
- Versions prior to Asterisk-addons 1.2.9
- Versions prior to Asterisk-addons 1.4.7
Asterisk-addons is prone to a remote denial-of-service vulnerability that stems from a design error.
Successful exploits can crash the 'OOH323' channel driver of Asterisk-addons, causing denial-of-service conditions for legitimate users.
The vulnerability affects the following:
- Versions prior to Asterisk-addons 1.2.9
- Versions prior to Asterisk-addons 1.4.7
Exploit / POC
Asterisk-addons 'OOH323' Channel Driver Remote Denial of Service Vulnerability
Attackers can exploit this issue by using readily available networking utilities.
Attackers can exploit this issue by using readily available networking utilities.
Solution / Fix
Asterisk-addons 'OOH323' Channel Driver Remote Denial of Service Vulnerability
Solution:
The vendor has released an advisory along with updates. Please see the references for more information.
Solution:
The vendor has released an advisory along with updates. Please see the references for more information.
References
Asterisk-addons 'OOH323' Channel Driver Remote Denial of Service Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- Asterisk Project Security Advisory - AST-2008-009 (Asterisk)
- AST-2008-009: (Corrected subject) Remote crash vulnerability in ooh323 channel d ("Asterisk Security Team"
)