Digium Asterisk vulnerabilities

114 known vulnerabilities affecting digium/asterisk.

Total CVEs
114
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH37MEDIUM67LOW5

Vulnerabilities

Page 5 of 6
CVE-2011-2536MEDIUMCVSS 5.0v1.8.0v1.8.1+110 more2011-07-06
CVE-2011-2536 [MEDIUM] CWE-200 CVE-2011-2536: chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1 chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote
nvdosv
CVE-2011-2535MEDIUMCVSS 5.0v1.8.0v1.8.1+107 more2011-07-06
CVE-2011-2535 [MEDIUM] CWE-20 CVE-2011-2535: chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before C.3.7.3, accesses a memory address contained in an option control frame, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecifie
nvdosv
CVE-2011-2529MEDIUMCVSS 5.0v1.6.0v1.6.0.1+83 more2011-07-06
CVE-2011-2529 [MEDIUM] CWE-119 CVE-2011-2529: chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x befor chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.
nvdosv
CVE-2011-2666MEDIUMCVSS 5.0v1.6.2.0v1.6.2.1+86 more2011-07-06
CVE-2011-2666 [MEDIUM] CVE-2011-2666: The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 a The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vu
nvdosv
CVE-2011-2665MEDIUMCVSS 5.0v1.8.0v1.8.1+14 more2011-07-06
CVE-2011-2665 [MEDIUM] CVE-2011-2665: reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.3 allows remot reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.3 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a SIP packet with a Contact header that lacks a < (less than) character.
nvdosv
CVE-2011-2216MEDIUMCVSS 5.0v1.8.0v1.8.1+13 more2011-06-06
CVE-2011-2216 [MEDIUM] CVE-2011-2216: reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not ini reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.
nvdosv
CVE-2011-1599CRITICALCVSS 9.0v1.4.0v1.4.1+121 more2011-04-27
CVE-2011-1599 [CRITICAL] CWE-20 CVE-2011-1599: manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6 manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system privilege, which allows remote authenticated users to execute arbitrary commands via an Originate actio
nvdosv
CVE-2011-1507MEDIUMCVSS 5.0v1.4.0v1.4.1+121 more2011-04-27
CVE-2011-1507 [MEDIUM] CWE-399 CVE-2011-1507: Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space ex
nvdosv
CVE-2011-1174MEDIUMCVSS 5.0v1.6.1v1.6.1.0+45 more2011-03-31
CVE-2011-1174 [MEDIUM] CWE-399 CVE-2011-1174: manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x befo manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a series of manager sessions involving invalid data.
nvdosv
CVE-2011-1175MEDIUMCVSS 5.0v1.6.1v1.6.1.0+42 more2011-03-31
CVE-2011-1175 [MEDIUM] CVE-2011-1175: tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2 tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2.17.1, and 1.8.x before 1.8.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by establishing many short TCP sessions to services that use a certain TLS API.
nvdosv
CVE-2011-1147MEDIUMCVSS 6.8v1.4.0v1.4.1+108 more2011-03-15
CVE-2011-1147 [MEDIUM] CWE-119 CVE-2011-1147: Multiple stack-based and heap-based buffer overflows in the (1) decode_open_type and (2) udptl_rx_pa Multiple stack-based and heap-based buffer overflows in the (1) decode_open_type and (2) udptl_rx_packet functions in main/udptl.c in Asterisk Open Source 1.4.x before 1.4.39.2, 1.6.1.x before 1.6.1.22, 1.6.2.x before 1.6.2.16.2, and 1.8 before 1.8.2.4; Business Edition C.x.x before C.3.6.3; AsteriskNOW 1.5; and s800i (Asterisk Appliance), when T.38 s
nvdosv
CVE-2011-0495MEDIUMCVSS 6.0fixed in c.3.6.2≥ 1.2.0, ≤ 1.2.40+7 more2011-01-20
CVE-2011-0495 [MEDIUM] CWE-787 CVE-2011-0495: Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source b Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving t
nvdosv
CVE-2010-1224MEDIUMCVSS 4.3v1.6.0v1.6.0.1+42 more2010-04-01
CVE-2010-1224 [MEDIUM] CWE-264 CVE-2010-1224: main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x bef main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x before 1.6.2.5 does not properly enforce remote host access controls when CIDR notation "/0" is used in permit= and deny= configuration rules, which causes an improper arithmetic shift and might allow remote attackers to bypass ACL rules and access service
nvdosv
CVE-2010-0685MEDIUMCVSS 5.0v1.2.0v1.2.1+95 more2010-02-23
CVE-2010-0685 [MEDIUM] CVE-2010-0685: The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asteri The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable and wildcard pattern matches, allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the variable is expanded, as demonstra
nvdosv
CVE-2009-4055MEDIUMCVSS 5.0v1.2.0v1.2.1+129 more2009-12-02
CVE-2009-4055 [MEDIUM] CVE-2009-4055: rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, a rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.x before B.2.5.13, C.2.x.x before C.2.4.6, and C.3.x.x before C.3.2.3; and s800i 1.3.x before 1.3.0.6 allows remote attackers to cause a denial of service (daemon crash) via an RTP comfort noise payload with a lo
nvdosv
CVE-2009-3727MEDIUMCVSS 5.0v1.2.0v1.2.1+126 more2009-11-10
CVE-2009-3727 [MEDIUM] CWE-200 CVE-2009-3727: Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1. Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which al
nvdosv
CVE-2009-2726HIGHCVSS 7.8fixed in b.2.5.9≥ c.2.0, ≤ c.2.4.1+5 more2009-08-12
CVE-2009-2726 [HIGH] CWE-770 CVE-2009-2726: The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x b The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style func
nvdosv
CVE-2009-2651MEDIUMCVSS 5.0v1.6.12009-07-30
CVE-2009-2651 [MEDIUM] CWE-399 CVE-2009-2651: main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer.
nvdosv
CVE-2009-0871LOWCVSS 3.5v1.4.22v1.4.23+9 more2009-03-11
CVE-2009-0871 [LOW] CWE-20 CVE-2009-0871: The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1 The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in
nvd
CVE-2007-6171HIGHCVSS 7.5≥ 1.4.0, < 1.4.15vc.1.02007-11-30
CVE-2007-6171 [HIGH] CWE-89 CVE-2007-6171: SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x bef SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
nvdosv