CVE-2011-2216Asterisk vulnerability

8 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
3.5%
top 12.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateMay 14

Description

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/asterisk< asterisk 1:1.8.4.2-1 (bullseye)
Debiandigium/asterisk< 1:1.8.4.2-1
NVDdigium/asterisk15 versions+14

🔴Vulnerability Details

2
GHSA
GHSA-q7w4-fcc5-r63h: reqresp_parser2022-05-14
OSV
CVE-2011-2216: reqresp_parser2011-06-06

💥Exploits & PoCs

1
Exploit-DB
WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting2015-03-03

📋Vendor Advisories

1
Debian
CVE-2011-2216: asterisk - reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before ...2011

💬Community

3
Bugzilla
CVE-2011-2216 Asterisk: Remote DoS (crash) in SIP channel driver (AST-2011-007) [epel-6]2011-06-03
Bugzilla
CVE-2011-2216 Asterisk: Remote DoS (crash) in SIP channel driver (AST-2011-007)2011-06-03
Bugzilla
CVE-2011-2216 Asterisk: Remote DoS (crash) in SIP channel driver (AST-2011-007) [fedora-15]2011-06-03