The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x prior to 1.2.23, 1.4.x prior to 1.4.9, and Asterisk Appliance Developer Kit prior to 0.6.0, when configured to allow unauthenticated calls, allows remote malicious users to cause a denial of service (resource exhaustion) via a flood of calls that do not complete a 3-way handshake, which causes an ast_channel to be allocated but not released.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
digium asterisk |
||
digium asterisk appliance developer kit |