Asterisk IAX2 Unauthenticated Session Handling Remote Denial of Service Vulnerability
BID:32773
Info
Asterisk IAX2 Unauthenticated Session Handling Remote Denial of Service Vulnerability
| Bugtraq ID: | 32773 |
| Class: | Design Error |
| CVE: |
CVE-2008-5558 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2008 12:00AM |
| Updated: | May 05 2009 01:37AM |
| Credit: | Asterisk |
| Vulnerable: |
Gentoo Linux Asterisk Asterisk Business Edition B.2.5.5 Asterisk Asterisk Business Edition B.2.5.4 Asterisk Asterisk Business Edition B.2.5.3 Asterisk Asterisk Business Edition B.2.5.2 Asterisk Asterisk Business Edition B.2.5.1 Asterisk Asterisk Business Edition B.2.3.6 Asterisk Asterisk Business Edition B.2.3.5 Asterisk Asterisk 1.2.30 Asterisk Asterisk 1.2.29 Asterisk Asterisk 1.2.28 Asterisk Asterisk 1.2.27 Asterisk Asterisk 1.2.27 Asterisk Asterisk 1.2.26 Asterisk Asterisk 1.2.30.3 |
| Not Vulnerable: |
Asterisk Asterisk Business Edition B.2.5.6 Asterisk Asterisk 1.2.30.4 |
Discussion
Asterisk IAX2 Unauthenticated Session Handling Remote Denial of Service Vulnerability
Asterisk is prone to a remote denial-of-service vulnerability because it fails to handle remote unauthenticated sessions in a proper manner.
Attackers can exploit this issue by sending authentication requests that will crash the server and deny service to legitimate users.
Asterisk is prone to a remote denial-of-service vulnerability because it fails to handle remote unauthenticated sessions in a proper manner.
Attackers can exploit this issue by sending authentication requests that will crash the server and deny service to legitimate users.
Exploit / POC
Asterisk IAX2 Unauthenticated Session Handling Remote Denial of Service Vulnerability
An attacker can use system utilities to carry out this attack.
An attacker can use system utilities to carry out this attack.
Solution / Fix
Asterisk IAX2 Unauthenticated Session Handling Remote Denial of Service Vulnerability
Solution:
The vendor has released an advisory along with updates. Please see the references for more information.
Solution:
The vendor has released an advisory along with updates. Please see the references for more information.
References
Asterisk IAX2 Unauthenticated Session Handling Remote Denial of Service Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- AST-2008-012: Remote crash vulnerability in IAX2 ("Asterisk Security Team"
) - Asterisk Project Security Advisory - AST-2008-012 (Asterisk)