Digium

Asterisk

114 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.36%
  • Published 06.07.2011 19:55:03
  • Last modified 11.04.2025 00:51:21

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or p...

  • EPSS 0.18%
  • Published 06.07.2011 19:55:03
  • Last modified 11.04.2025 00:51:21

chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before C.3.7.3, accesses a memory address contained in an option control fram...

  • EPSS 0.19%
  • Published 06.07.2011 19:55:03
  • Last modified 11.04.2025 00:51:21

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates differen...

  • EPSS 2.32%
  • Published 06.07.2011 19:55:03
  • Last modified 11.04.2025 00:51:21

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.3 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a SIP packet with a Contact header that lacks a < (less than)...

  • EPSS 0.59%
  • Published 06.07.2011 19:55:03
  • Last modified 11.04.2025 00:51:21

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series...

  • EPSS 3.5%
  • Published 06.06.2011 19:55:03
  • Last modified 11.04.2025 00:51:21

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contac...

  • EPSS 0.15%
  • Published 27.04.2011 00:55:04
  • Last modified 11.04.2025 00:51:21

Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, ...

  • EPSS 0.34%
  • Published 27.04.2011 00:55:04
  • Last modified 11.04.2025 00:51:21

manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system p...

  • EPSS 0.29%
  • Published 31.03.2011 22:55:03
  • Last modified 11.04.2025 00:51:21

manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a series of manager sessions involving invalid data.

  • EPSS 0.28%
  • Published 31.03.2011 22:55:03
  • Last modified 11.04.2025 00:51:21

tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2.17.1, and 1.8.x before 1.8.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by establishing many ...