5
CVSSv2

CVE-2011-2529

Published: 06/07/2011 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x prior to 1.6.2.18.1 and 1.8.x prior to 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote malicious users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.6.0

digium asterisk 1.6.1

digium asterisk 1.6.1.2

digium asterisk 1.6.1.3

digium asterisk 1.6.0.26

digium asterisk 1.6.1.8

digium asterisk 1.6.1.18

digium asterisk 1.6.0.8

digium asterisk 1.6.0.11

digium asterisk 1.6.0.16

digium asterisk 1.6.0.21

digium asterisk 1.6.0.18

digium asterisk 1.6.0.13

digium asterisk 1.6.1.12

digium asterisk 1.6.1.19

digium asterisk 1.6.1.0

digium asterisk 1.6.1.13

digium asterisk 1.6.1.22

digium asterisk 1.6.0.5

digium asterisk 1.6.1.24

digium asterisk 1.6.2.0

digium asterisk 1.6.2.3

digium asterisk 1.6.2.4

digium asterisk 1.6.2.16.2

digium asterisk 1.6.2.6

digium asterisk 1.6.1.20

digium asterisk 1.6.1.4

digium asterisk 1.6.1.5

digium asterisk 1.6.0.23

digium asterisk 1.6.1.9

digium asterisk 1.6.0.9

digium asterisk 1.6.0.6

digium asterisk 1.6.0.15

digium asterisk 1.6.0.17

digium asterisk 1.6.1.10

digium asterisk 1.6.1.16

digium asterisk 1.6.0.3

digium asterisk 1.6.0.4

digium asterisk 1.6.2.16

digium asterisk 1.6.2.17

digium asterisk 1.6.2.17.1

digium asterisk 1.6.1.7

digium asterisk 1.6.0.10

digium asterisk 1.6.0.20

digium asterisk 1.6.0.14

digium asterisk 1.6.1.14

digium asterisk 1.6.1.23

digium asterisk 1.6.1.15

digium asterisk 1.6.2.16.1

digium asterisk 1.6.2.1

digium asterisk 1.6.2.2

digium asterisk 1.6.2.17.2

digium asterisk 1.6.2.18

digium asterisk 1.6.0.1

digium asterisk 1.6.1.1

digium asterisk 1.6.1.6

digium asterisk 1.6.0.24

digium asterisk 1.6.0.25

digium asterisk 1.6.1.17

digium asterisk 1.6.0.7

digium asterisk 1.6.0.22

digium asterisk 1.6.0.19

digium asterisk 1.6.0.12

digium asterisk 1.6.1.11

digium asterisk 1.6.1.21

digium asterisk 1.6.0.2

digium asterisk 1.6.2.15

digium asterisk 1.6.2.5

digium asterisk 1.6.2.17.3

digium asterisk 1.8.1.2

digium asterisk 1.8.1.1

digium asterisk 1.8.0

digium asterisk 1.8.4

digium asterisk 1.8.2.3

digium asterisk 1.8.3

digium asterisk 1.8.4.1

digium asterisk 1.8.1

digium asterisk 1.8.4.2

digium asterisk 1.8.3.1

digium asterisk 1.8.3.3

digium asterisk 1.8.2.2

digium asterisk 1.8.2.1

digium asterisk 1.8.2

digium asterisk 1.8.3.2

digium asterisk 1.8.2.4

Vendor Advisories

Debian Bug report logs - #631448 asterisk: AST-2011-010 (CVE-2011-2535) - crash due to using remote pointers Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debianor ...
Debian Bug report logs - #632029 asterisk: AST-2011-011 (CVE-2011-2536) Possible enumeration of SIP users Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debianorg&g ...
Debian Bug report logs - #631445 asterisk; AST-2011-009 - crash on malformed SIP packet Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debianorg> Date: Thu, 23 ...
Debian Bug report logs - #631446 asterisk: AST-2011-008 (CVE-2011-2529) - remote unauthenticated (null character) Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debi ...