Home page logo

fulldisclosure logo Full Disclosure mailing list archives

From: "Asterisk Security Team" <security () asterisk org>
Date: Wed, 16 Mar 2011 17:50:33 -0500

   Product            Asterisk                                                
   Summary            Resource exhaustion in Asterisk Manager Interface       
   Nature of Advisory Denial of Service                                       
   Susceptibility     Remote Unauthenticated Sessions if manager interface is 
   Severity           Moderate                                                
   Exploits Known     No                                                      
   Reported On        March 1, 2011                                           
   Reported By        Blake Cornell <blake () remoteorigin com>
   Posted On          March 16, 2011                                          
   Last Updated On    March 14, 2011                                          
   Advisory Contact   Terry Wilson <twilson () digium com>                       


               Rapidly opening manager connections, sending invalid data, and 
   Description closing the connection can cause Asterisk to exhaust available 
               CPU and memory resources. The manager interface is disabled by 


   Resolution Failed writes to manager clients are flagged and the connection 


   Affected Versions                 
   Product                           Release Series                           
   Asterisk Open Source              1.6.1.x         All versions             
   Asterisk Open Source              1.6.2.x         All versions             
   Asterisk Open Source              1.8.x           All versions             


   Corrected In                     
   Product                          Release                                   
   Asterisk Open Source   ,,             

   URL                                                                 Branch 
   http://downloads.asterisk.org/pub/security/AST-2011-003-1.6.1.diff  1.6.1  
   http://downloads.asterisk.org/pub/security/AST-2011-003-1.6.2.diff  1.6.2  
   http://downloads.asterisk.org/pub/security/AST-2011-003-1.8.diff    1.8    





   Asterisk Project Security Advisories are posted at                         
   This document may be superseded by later versions; if so, the latest       
   version will be posted at                                                  
   http://downloads.digium.com/pub/security/AST-2011-003.pdf and              


   Revision History       
   Date                   Editor                   Revisions Made             
   2011-03-14             Terry Wilson             Initial release            


Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • AST-2011-003: Asterisk Security Team (Mar 16)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]