CVE-2011-1174Asterisk vulnerability

CWE-3996 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 47.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 17

Description

manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a series of manager sessions involving invalid data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/asterisk< asterisk 1:1.8.3.3-1 (bullseye)
Debiandigium/asterisk< 1:1.8.3.3-1
NVDdigium/asterisk47 versions+46

🔴Vulnerability Details

2
GHSA
GHSA-j5wq-5rfm-xx8g: manager2022-05-17
OSV
CVE-2011-1174: manager2011-03-31

📋Vendor Advisories

1
Debian
CVE-2011-1174: asterisk - manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2....2011

💬Community

2
Bugzilla
CVE-2011-1174 asterisk: resource exhaustion in Asterisk Manager Interface (AST-2011-003)2011-03-17
Bugzilla
CVE-2011-0284 krb5 (krb5kdc): Double-free flaw by handling error messages upon receiving certain AS_REQ's (MITKRB5-SA-2011-003)2011-02-01