Asterisk IAX2 Poke Packet Processing Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1020535
|
|
SecurityTracker URL: http://securitytracker.com/id?1020535
|
|
CVE Reference: CVE-2008-3263
(Links to External Site)
|
Date: Jul 23 2008
|
Impact: Denial of service via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 1.2 prior to 1.2.30, 1.4 prior to 1.4.21.2
|
Description: A vulnerability was reported in Asterisk. A remote user can cause denial of service conditions.
A remote user can send a flood of specially crafted IAX2 POKE requests to consume all available IAX2 protocol call numbers on the
target system, preventing other IAX2 calls from getting through.
The vendor was notified on July 18, 2008.
A demonstration
exploit is available at:
http://downloads.securityfocus.com/vulnerabilities/exploits/30321.pl
Jeremy McNamara reported this
vulnerability.
|
Impact: A remote user can consume all available IAX2 call numbers on the target system, preventing additional calls.
|
Solution: The vendor has issued a fixed version (1.2.30, 1.4.21.2).
The vendor's advisory is available at:
http://downloads.digium.com/pub/security/AST-2008-010.html
|
Vendor URL: downloads.digium.com/pub/security/AST-2008-010.html (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|