Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities
BID:36015
Info
Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 36015 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2726 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2009 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | Mu Dynamics research team |
| Vulnerable: |
Gentoo Linux Asterisk Asterisk 1.6.3 Asterisk Asterisk 1.6.2 Asterisk Asterisk 1.6.1 |
| Not Vulnerable: |
Asterisk Asterisk 1.6.4 |
Discussion
Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities
Asterisk is prone to multiple remote denial-of-service vulnerabilities.
Successful exploits can crash the SIP channel driver, resulting in denial-of-service conditions for legitimate users.
The issues affect the Asterisk 1.6.1.
NOTE: Other versions may also include the affected code but may not be exploitable because they do not allow SIP packets to exceed 1500 bytes total.
Asterisk is prone to multiple remote denial-of-service vulnerabilities.
Successful exploits can crash the SIP channel driver, resulting in denial-of-service conditions for legitimate users.
The issues affect the Asterisk 1.6.1.
NOTE: Other versions may also include the affected code but may not be exploitable because they do not allow SIP packets to exceed 1500 bytes total.
Exploit / POC
Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities
Attackers can exploit these issues by using readily available networking utilities.
Attackers can exploit these issues by using readily available networking utilities.
Solution / Fix
Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities
References:
References:
- Asterisk Homepage (Asterisk)
- AST-2009-005: Remote Crash Vulnerability in SIP channel driver ("Asterisk Security Team"
) - Asterisk Project Security Advisory - AST-2009-005 (Asterisk)
- Multiple sscanf vulnerabilities in Asterisk [MU-200908-01] (Mu Dynamics)