|
|
|
Vulnerability Note VU#228032Asterisk null pointer dereference remote pre-authentication DoS vulnerabilityOverviewAsterisk contains a null pointer dereference vulnerability that may allow a remote, unauthenticated attacker to cause a denial-of-service condition on a vulnerable system.I. DescriptionAsterisk is a popular PBX application with VoIP support. Asterisk contains a null pointer dereference vulnerability that can allow a remote, unauthenticated attacker to crash the Asterisk server software with a specially crafted Session Initiation Protocol (SIP) packet (typically udp/5060).II. ImpactA remote, unauthenticated attacker may be able to cause a denial of service on a vulnerable server.III. SolutionApply an updateThis issue is addressed in Asterisk versions 1.4.1 and 1.2.16.
References
This vulnerability was reported by the Mu Security research team. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||