Asterisk IAX2 Poke Packet Processing Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1020535 |
|
SecurityTracker URL: http://securitytracker.com/id/1020535
|
|
CVE Reference:
CVE-2008-3263
(Links to External Site)
|
Date: Jul 23 2008
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 1.2 prior to 1.2.30, 1.4 prior to 1.4.21.2
|
Description:
A vulnerability was reported in Asterisk. A remote user can cause denial of service conditions.
A remote user can send a flood of specially crafted IAX2 POKE requests to consume all available IAX2 protocol call numbers on the target system, preventing other IAX2 calls from getting through.
The vendor was notified on July 18, 2008.
A demonstration exploit is available at:
http://downloads.securityfocus.com/vulnerabilities/exploits/30321.pl
Jeremy McNamara reported this vulnerability.
|
Impact:
A remote user can consume all available IAX2 call numbers on the target system, preventing additional calls.
|
Solution:
The vendor has issued a fixed version (1.2.30, 1.4.21.2).
The vendor's advisory is available at:
http://downloads.digium.com/pub/security/AST-2008-010.html
|
Vendor URL: downloads.digium.com/pub/security/AST-2008-010.html (Links to External Site)
|
Cause:
State error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|