5
CVSSv2

CVE-2009-3727

Published: 10/11/2009 Updated: 23/12/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Asterisk Open Source 1.2.x prior to 1.2.35, 1.4.x prior to 1.4.26.3, 1.6.0.x prior to 1.6.0.17, and 1.6.1.x prior to 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x prior to 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which allows remote malicious users to enumerate valid usernames via multiple crafted REGISTER messages with inconsistent usernames in the URI in the To header and the Digest in the Authorization header.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.2.0

digium asterisk 1.2.12

digium asterisk 1.2.12.1

digium asterisk 1.2.16

digium asterisk 1.2.17

digium asterisk 1.2.2

digium asterisk 1.2.20

digium asterisk 1.2.22

digium asterisk 1.2.23

digium asterisk 1.2.26.1

digium asterisk 1.2.3

digium asterisk 1.2.31.1

digium asterisk 1.2.32

digium asterisk 1.2.33

digium asterisk 1.4.1

digium asterisk 1.4.10

digium asterisk 1.4.15

digium asterisk 1.4.16

digium asterisk 1.4.19

digium asterisk 1.4.20

digium asterisk 1.4.20.1

digium asterisk 1.4.22

digium asterisk 1.4.23

digium asterisk 1.4.25

digium asterisk 1.4.25.1

digium asterisk 1.4.26

digium asterisk 1.4.7.1

digium asterisk 1.4.8

digium asterisk 1.6.0.4

digium asterisk 1.6.0.5

digium asterisk 1.6.0

digium asterisk 1.6.0.8

digium asterisk 1.6.0.9

digium asterisk 1.6.0.15

digium asterisk 1.6.0.16

digium asterisk 1.6.1.0

digium asterisk 1.6.1.1

digium asterisk 1.6.1.10

digium asterisk 1.6.1.6

digium asterisk 1.6.1.7

digium asterisk 1.2.10

digium asterisk 1.2.11

digium asterisk 1.2.14

digium asterisk 1.2.15

digium asterisk 1.2.18

digium asterisk 1.2.19

digium asterisk 1.2.21

digium asterisk 1.2.21.1

digium asterisk 1.2.25

digium asterisk 1.2.27

digium asterisk 1.2.28

digium asterisk 1.2.30.2

digium asterisk 1.2.30.3

digium asterisk 1.4.0

digium asterisk 1.4.12

digium asterisk 1.4.12.1

digium asterisk 1.4.17

digium asterisk 1.4.18

digium asterisk 1.4.2

digium asterisk 1.4.21

digium asterisk 1.4.21.1

digium asterisk 1.4.22.1

digium asterisk 1.4.22.2

digium asterisk 1.4.23.2

digium asterisk 1.4.24

digium asterisk 1.4.4

digium asterisk 1.4.5

digium asterisk 1.6.0.1

digium asterisk 1.6.0.2

digium asterisk 1.6.0.11

digium asterisk 1.6.1.3

digium asterisk 1.6.1.4

digium asterisk 1.2.26

digium asterisk 1.2.28.1

digium asterisk 1.2.29

digium asterisk 1.2.30.4

digium asterisk 1.2.31

digium asterisk 1.4.13

digium asterisk 1.4.14

digium asterisk 1.4.21.2

digium asterisk 1.4.24.1

digium asterisk 1.4.6

digium asterisk 1.4.7

digium asterisk 1.6.0.3

digium asterisk 1.6.0.6

digium asterisk 1.6.0.7

digium asterisk 1.6.0.14

digium asterisk 1.6.1.5

digium asterisk 1.2.1

digium asterisk 1.2.13

digium asterisk 1.2.24

digium asterisk 1.2.26.2

digium asterisk 1.2.30

digium asterisk 1.2.30.1

digium asterisk 1.2.34

digium asterisk 1.4.10.1

digium asterisk 1.4.11

digium asterisk 1.4.16.1

digium asterisk 1.4.16.2

digium asterisk 1.4.19.1

digium asterisk 1.4.19.2

digium asterisk 1.4.23.1

digium asterisk 1.4.26.1

digium asterisk 1.4.26.2

digium asterisk 1.4.3

digium asterisk 1.4.9

digium asterisk 1.6.0.10

digium asterisk 1.6.1.2

digium asterisk 1.6.1.8

digium asterisknow 1.5

digium s800i 1.3.0.3

digium s800i 1.3.0.2

digium s800i 1.3.0

digium s800i 1.3.0.4

digium asterisk b.2.2.1

digium asterisk b.2.3.1

digium asterisk b.2.5.1

digium asterisk b.2.5.2

digium asterisk b.1.3.2

digium asterisk c.2.3

digium asterisk b.2.3.4

digium asterisk b.2.3.5

digium asterisk b

digium asterisk c

digium asterisk c.3.0

digium asterisk b.1.3.3

digium asterisk b.2.2.0

digium asterisk b.2.3.6

digium asterisk b.2.5.0

digium asterisk b.2.3.2

digium asterisk b.2.3.3

digium asterisk b.2.5.3

digium asterisk a

Vendor Advisories

Debian Bug report logs - #559103 CVE-2009-4055: RTP Remote Crash Vulnerability Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 Dec 200 ...
Debian Bug report logs - #522528 AST-2009-003: SIP responses expose valid usernames Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrircohen@xorcomcom> Date: Sat, ...