5
CVSSv2

CVE-2011-2536

Published: 06/07/2011 Updated: 07/09/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x prior to 1.4.41.2, 1.6.2.x prior to 1.6.2.18.2, and 1.8.x prior to 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote malicious users to enumerate account names via a series of requests.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.8.1.2

digium asterisk 1.8.1

digium asterisk 1.8.0

digium asterisk 1.8.3

digium asterisk 1.8.4.3

digium asterisk 1.8.4

digium asterisk 1.8.4.1

digium asterisk 1.8.2

digium asterisk 1.8.2.4

digium asterisk 1.8.4.2

digium asterisk 1.8.3.3

digium asterisk 1.8.2.2

digium asterisk 1.8.2.1

digium asterisk 1.8.3.2

digium asterisk 1.8.1.1

digium asterisk 1.8.2.3

digium asterisk 1.8.3.1

digium asterisk 1.6.2.5

digium asterisk 1.6.2.16.1

digium asterisk 1.6.2.0

digium asterisk 1.6.2.15

digium asterisk 1.6.2.17

digium asterisk 1.6.2.17.1

digium asterisk 1.6.2.6

digium asterisk 1.6.2.16

digium asterisk 1.6.2.3

digium asterisk 1.6.2.4

digium asterisk 1.6.2.18

digium asterisk 1.6.2.17.3

digium asterisk 1.6.2.18.1

digium asterisk 1.6.2.16.2

digium asterisk 1.6.2.1

digium asterisk 1.6.2.2

digium asterisk 1.6.2.17.2

digium asterisk 1.4.19

digium asterisk 1.4.29

digium asterisk 1.4.19.2

digium asterisk 1.4.30

digium asterisk 1.4.20

digium asterisk 1.4.1

digium asterisk 1.4.0

digium asterisk 1.4.16.1

digium asterisk 1.4.16

digium asterisk 1.4.14

digium asterisk 1.4.26

digium asterisk 1.4.29.1

digium asterisk 1.4.19.1

digium asterisk 1.4.31

digium asterisk 1.4.21.1

digium asterisk 1.4.21.2

digium asterisk 1.4.15

digium asterisk 1.4.13

digium asterisk 1.4.23

digium asterisk 1.4.28

digium asterisk 1.4.21

digium asterisk 1.4.12.1

digium asterisk 1.4.11

digium asterisk 1.4.18

digium asterisk 1.4.23.1

digium asterisk 1.4.26.1

digium asterisk 1.4.22

digium asterisk 1.4.25

digium asterisk 1.4.33

digium asterisk 1.4.33.1

digium asterisk 1.4.27

digium asterisk 1.4.3

digium asterisk 1.4.38

digium asterisk 1.4.4

digium asterisk 1.4.6

digium asterisk 1.4.40.2

digium asterisk 1.4.41

digium asterisk 1.4.2

digium asterisk 1.4.20.1

digium asterisk 1.4.10.1

digium asterisk 1.4.10

digium asterisk 1.4.17

digium asterisk 1.4.16.2

digium asterisk 1.4.25.1

digium asterisk 1.4.26.3

digium asterisk 1.4.23.2

digium asterisk 1.4.27.1

digium asterisk 1.4.34

digium asterisk 1.4.12

digium asterisk 1.4.7

digium asterisk 1.4.39

digium asterisk 1.4.39.1

digium asterisk 1.4.40

digium asterisk 1.4.40.1

digium asterisk 1.4.26.2

digium asterisk 1.4.22.1

digium asterisk 1.4.24

digium asterisk 1.4.35

digium asterisk 1.4.32

digium asterisk 1.4.5

digium asterisk 1.4.7.1

digium asterisk 1.4.37

digium asterisk 1.4.36

digium asterisk 1.4.39.2

digium asterisk 1.4.22.2

digium asterisk 1.4.24.1

digium asterisk 1.4.8

digium asterisk 1.4.9

digium asterisk 1.4.41.1

digium asterisk c.3.1.1

digium asterisk c.3.6.2

digium asterisk c.3.0

digium asterisk c.3.1.0

digium asterisk c.3.3.2

digium asterisk c.3.6.3

digium asterisk c.3.6.4

digium asterisk c.3.2.3

digium asterisk c.3.2.2

Vendor Advisories

Debian Bug report logs - #631448 asterisk: AST-2011-010 (CVE-2011-2535) - crash due to using remote pointers Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debianor ...
Debian Bug report logs - #632029 asterisk: AST-2011-011 (CVE-2011-2536) Possible enumeration of SIP users Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debianorg&g ...
Debian Bug report logs - #631446 asterisk: AST-2011-008 (CVE-2011-2529) - remote unauthenticated (null character) Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrir@debi ...