Asterisk Manager Interface Remote Denial of Service Vulnerability
BID:46897
Info
Asterisk Manager Interface Remote Denial of Service Vulnerability
| Bugtraq ID: | 46897 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1174 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2011 12:00AM |
| Updated: | May 07 2015 05:01PM |
| Credit: | Blake Cornell |
| Vulnerable: |
Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Asterisk Asterisk 1.8.2 4 Asterisk Asterisk 1.8.1 Asterisk Asterisk 1.8 Asterisk Asterisk 1.6.2 16.2 Asterisk Asterisk 1.6.2 .5 Asterisk Asterisk 1.6.2 Asterisk Asterisk 1.6.1 22 Asterisk Asterisk 1.6.1 11 Asterisk Asterisk 1.6.1 0-rc2 Asterisk Asterisk 1.6.1 0-rc1 Asterisk Asterisk 1.6.1 .9 Asterisk Asterisk 1.6.1 .6 Asterisk Asterisk 1.6.1 .5 Asterisk Asterisk 1.6.1 .17 Asterisk Asterisk 1.6.1 Asterisk Asterisk 1.8.2.1 Asterisk Asterisk 1.8.1.2 Asterisk Asterisk 1.8 Asterisk Asterisk 1.6.2.2 Asterisk Asterisk 1.6.2.16.1 Asterisk Asterisk 1.6.2.15.1 Asterisk Asterisk 1.6.1.8 Asterisk Asterisk 1.6.1.7 Asterisk Asterisk 1.6.1.21 Asterisk Asterisk 1.6.1.14 |
| Not Vulnerable: |
Asterisk Asterisk 1.8.3.1 Asterisk Asterisk 1.6.2.17.1 Asterisk Asterisk 1.6.1.23 |
Discussion
Asterisk Manager Interface Remote Denial of Service Vulnerability
Asterisk is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause Asterisk to exhaust available CPU and memory resources and make the affected application unresponsive, denying service to legitimate users.
Asterisk series 1.6.1.x, 1.6.2.x, and 1.8.x are vulnerable.
Asterisk is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause Asterisk to exhaust available CPU and memory resources and make the affected application unresponsive, denying service to legitimate users.
Asterisk series 1.6.1.x, 1.6.2.x, and 1.8.x are vulnerable.
Solution / Fix
Asterisk Manager Interface Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.