Asterisk Security Advisory – AST-2009-004


Asterisk The Open Source PBX & Telephony Platform

Asterisk The Open Source PBX & Telephony Platform

Asterisk Project Security AdvisoryAST-2009-004

An attacker can cause Asterisk to crash remotely by sending malformed RTP text frames. While the attacker can cause Asterisk to crash, he cannot execute arbitrary remote code with this exploit.
Users should upgrade to a version listed in the “Corrected In” section below.

Product

Asterisk

Summary

Remote Crash Vulnerability in RTP stack

Nature of Advisory

Exploitable Crash

Susceptibility

Remote unauthenticated sessions

Severity

Critical

Exploits Known

No

Reported On

July 27, 2009

Reported By

Marcus Hunger <hunger AT sipgate DOT de>

Posted On

August 2, 2009

Last Updated On

August 2, 2009

Advisory Contact

Mark Michelson <mmichelson AT digium DOT com>

CVE Name

Description

An attacker can cause Asterisk to crash remotely by sending malformed RTP text frames. While the attacker can cause Asterisk to crash, he cannot execute arbitrary remote code with this exploit.

Resolution

Users should upgrade to a version listed in the “Corrected In” section below.

Affected Versions

Product

Release Series

Asterisk Open Source

1.2.x

Unaffected

Asterisk Open Source

1.4.x

Unaffected

Asterisk Open Source

1.6.x

All 1.6.1 versions

Asterisk Addons

1.2.x

Unaffected

Asterisk Addons

1.4.x

Unaffected

Asterisk Addons

1.6.x

Unaffected

Asterisk Business Edition

A.x.x

Unaffected

Asterisk Business Edition

B.x.x

Unaffected

Asterisk Business Edition

C.x.x

Unaffected

AsteriskNOW

1.5

Unaffected

s800i (Asterisk Appliance)

1.2.x

Unaffected

Corrected In

Product

Release

Open Source Asterisk 1.6.1

1.6.1.2

Patches

SVN URL

Version

http://downloads.digium.com/pub/security/AST-2009-004-1.6.1.diff.txt

1.6.1

Links

Asterisk Project Security Advisories are posted at http://www.asterisk.org/security. This document may be superseded by later versions; if so, the latest version will be posted at http://downloads.digium.com/pub/security/AST-2009-004.pdf and http://downloads.digium.com/pub/security/AST-2009-004.html

Revision History

Date

Editor

Revisions Made

27 Jul, 2009 Mark Michelson Initial Draft
31 Jul, 2009 Mark Michelson Added sentence about how remote code cannot be executed.
August 2, 2009 Tilghman Lesher Public release

Asterisk Project Security AdvisoryAST-2009-004

News in the mail list asterisk-security:

News in the mail list asterisk-announce:

News in the mail list asterisk-users:

News in the mail list asterisk-dev:

Share and Enjoy:
  • PDF
  • Print
  • email
  • RSS
  • Twitthis
  • Google Bookmarks
  • Twitter
  • Facebook
  • Digg
  • Technorati
  • MySpace
  • del.icio.us
  • LinkedIn
  • Slashdot
  • Reddit
  • Yahoo! Bookmarks
  • Live
  • MSN Reporter
  • Yahoo! Buzz
  • Ping.fm
  • Mixx
  • MyShare
  • SphereIt
  • Yigg
  • BlinkList
  • blogmarks
  • Blogosphere News
  • Current
  • Diigo
  • DZone
  • Fleck
  • FriendFeed
  • HelloTxt
  • Suggest to Techmeme via Twitter
  • ThisNext
  • Sphinn
  • BarraPunto
  • Bitacoras.com
  • BlogMemes Fr
  • BlogMemes Sp
  • blogtercimlap
  • co.mments
  • connotea
  • Design Float
  • DotNetKicks
  • eKudos
  • Fark
  • Faves
  • FSDaily
  • Global Grind
  • Gwar
  • HackerNews
  • Haohao
  • HealthRanker
  • Hemidemi
  • Hyves
  • Identi.ca
  • IndianPad
  • Internetmedia
  • Kirtsy
  • laaik.it
  • LinkaGoGo
  • LinkArena
  • Linkter
  • Meneame
  • MisterWong
  • MisterWong.DE
  • muti
  • N4G
  • Netvibes
  • Netvouz
  • NewsVine
  • NuJIJ
  • Posterous
  • ppnow
  • Propeller
  • Ratimarks
  • Rec6
  • Scoopeo
  • Segnalo
  • Simpy
  • Socialogs
  • StumbleUpon
  • Symbaloo
  • Tipd
  • Tumblr
  • Upnews
  • Webnews.de
  • Webride
  • Wikio
  • Wikio FR
  • Wikio IT
  • Wists
  • Wykop
  • Xerpi
  • 豆瓣
  • 豆瓣九点
  • Add to favorites
  • Blogplay
  • Diggita
  • LaTafanera
  • MOB
  • QQ书签
  • SheToldMe
  • viadeo FR

Related Posts

  1. Asterisk Security Advisory – AST-2009-005: Remote Crash Vulnerability in SIP channel driver
  2. Asterisk 1.6.0.11-rc2, 1.6.1.2, 1.6.1.3-rc1, and 1.6.2.0-beta4 Release Announcement
  3. Asterisk Security Advisory – AST-2010-001: T.38 Remote Crash Vulnerability
  4. Asterisk Security Advisory – AST-2011-002: Multiple array overflow and crash vulnerabilities in UDPTL code
  5. Asterisk 1.2.34, Asterisk 1.4.26.1, Asterisk 1.6.0.13, and Asterisk 1.6.1.4 released

, , , ,

  1. No comments yet.

You must be logged in to post a comment.