Asterisk RTP Text Frames Processing Remote Denial of Service Vulnerability
BID:35837
Info
Asterisk RTP Text Frames Processing Remote Denial of Service Vulnerability
| Bugtraq ID: | 35837 |
| Class: | Unknown |
| CVE: |
CVE-2009-2651 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2009 12:00AM |
| Updated: | Apr 16 2015 06:12PM |
| Credit: | Marcus Hunger |
| Vulnerable: |
Asterisk Asterisk 1.6.1 0-rc2 Asterisk Asterisk 1.6.1 0-rc1 Asterisk Asterisk 1.6.1 |
| Not Vulnerable: | |
Discussion
Asterisk RTP Text Frames Processing Remote Denial of Service Vulnerability
Asterisk is prone to a remote denial-of-service vulnerability because it fails to properly handle malformed RTP text frames.
Successful exploits can crash the application, resulting in denial-of-service conditions for legitimate users.
Asterisk is prone to a remote denial-of-service vulnerability because it fails to properly handle malformed RTP text frames.
Successful exploits can crash the application, resulting in denial-of-service conditions for legitimate users.
Exploit / POC
Asterisk RTP Text Frames Processing Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Asterisk RTP Text Frames Processing Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Asterisk RTP Text Frames Processing Remote Denial of Service Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- AST-2009-004: Remote Crash Vulnerability in RTP stack ("Asterisk Security Team"
) - AST-2009-004-1.6.1 patch details (Asterisk)
- Asterisk Project Security Advisory - AST-2009-004 (Asterisk)