New User, Welcome!     Login

Next Page >>

Advisory Contact

AST-2011-005: File Descriptor Resource Exhaustion

     Exploits Known   Yes                                                     
      Reported On     March 18, 2011                                          
      Reported By     Tzafrir Cohen < tzafrir.cohen AT xorcom DOT com >       
       Posted On      April 21, 2011                                          
    Last Updated On   April 21, 2011                                          
    Advisory Contact  Matthew Nicholson <mnicholson@digium.com>               
        CVE Name      CVE-2011-1507                                           

   Description On systems that have the Asterisk Manager Interface, Skinny,   
               SIP over TCP, or the built in HTTP server enabled, it is       
               possible for an attacker to open as many connections to        

AST-2008-009: (Corrected subject) Remote crash vulnerability in ooh323 channel driver

   |--------------------+---------------------------------------------------|
   |     Posted On      | June 4, 2008                                      |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | June 4, 2008                                      |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Mark Michelson <mmichelson AT digium DOT com>     |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2008-2543                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2007-021: Crash from invalid/corrupted MIME bodies when using voicemail with IMAP storage

   |--------------------+---------------------------------------------------|
   |     Posted On      | August 24, 2007                                   |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | August 24, 2007                                   |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Mark Michelson <mmichelson@digium.com>            |
   |--------------------+---------------------------------------------------|
   |      CVE Name      |CVE-2007-4521                                      |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

ASA-2007-018: Resource exhaustion vulnerability in IAX2 channel driver

   |--------------------+---------------------------------------------------|
   |     Posted On      | July 23, 2007                                     |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | July 25, 2007                                     |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Russell Bryant <russell@digium.com>               |
   |--------------------+---------------------------------------------------|
   |      CVE Name      |                                                   |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2007-025 - SQL Injection issue in res_config_pgsql

   |----------------------+-------------------------------------------------|
   |      Posted On       | November 29, 2007                               |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | November 29, 2007                               |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Tilghman Lesher <tlesher AT digium DOT com>     |
   |----------------------+-------------------------------------------------|
   |       CVE Name       |                                                 |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2011-012: Remote crash vulnerability in SIP channel driver

       Exploits Known     No                                                  
        Reported On       October 4, 2011                                     
        Reported By       Ehsan Foroughi                                      
         Posted On        October 17, 2011                                    
      Last Updated On     October 17, 2011                                    
      Advisory Contact    Terry Wilson <twilson@digium.com>                   
          CVE Name        CVE-2011-4063                                       

    Description  A remote authenticated user can cause a crash with a         
                 malformed request due to an unitialized variable.            


AST-2009-009: Cross-site AJAX request vulnerability

   |----------------------+-------------------------------------------------|
   |      Posted On       | November 4, 2009                                |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | November 4, 2009                                |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Joshua Colp <jcolp AT digium DOT com>           |
   |----------------------+-------------------------------------------------|
   |       CVE Name       | CVE-2008-7220                                   |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2011-013: Possible remote enumeration of SIP endpoints with differing NAT settings

      Exploits Known    Yes                                                   
       Reported On      2011-07-18                                            
       Reported By      Ben Williams                                          
        Posted On       
     Last Updated On    December 7, 2011                                      
     Advisory Contact   Terry Wilson <twilson@digium.com>                     
         CVE Name       

    Description  It is possible to enumerate SIP usernames when the general   
                 and user/peer NAT settings differ in whether to respond to   
                 the port a request is sent from or the port listed for       

AST-2008-001: Crash from transfer using BYE with Also header

    |---------------------+--------------------------------------------------|
    |      Posted On      | January 2, 2008                                  |
    |---------------------+--------------------------------------------------|
    |   Last Updated On   | January 2, 2008                                  |
    |---------------------+--------------------------------------------------|
    |  Advisory Contact   | Joshua Colp <jcolp@digium.com>                   |
    |---------------------+--------------------------------------------------|
    |      CVE Name       |                                                  |
    +------------------------------------------------------------------------+

    +------------------------------------------------------------------------+

AST-2007-026 - SQL Injection issue in cdr_pgsql

   |----------------------+-------------------------------------------------|
   |      Posted On       | November 29, 2007                               |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | November 29, 2007                               |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Tilghman Lesher <tlesher AT digium DOT com>     |
   |----------------------+-------------------------------------------------|
   |       CVE Name       |                                                 |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2011-007

   |---------------------+--------------------------------------------------|
   |      Posted On      | June 02, 2011                                    |
   |---------------------+--------------------------------------------------|
   |   Last Updated On   | June 02, 2011                                    |
   |---------------------+--------------------------------------------------|
   |  Advisory Contact   | Jonathan Rose jrose@digium.com                   |
   |---------------------+--------------------------------------------------|
   |      CVE Name       | CVE-2011-2216                                    |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2007-020: Resource Exhaustion Vulnerability in Asterisk SIP channel driver

   |--------------------+---------------------------------------------------|
   |     Posted On      | August 21, 2007                                   |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | August 21, 2007                                   |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Russell Bryant <russell@digium.com>               |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2007-4455                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2009-005: Remote Crash Vulnerability in SIP channel driver

   |---------------------+--------------------------------------------------|
   |      Posted On      | August 10, 2009                                  |
   |---------------------+--------------------------------------------------|
   |   Last Updated On   | August 10, 2009                                  |
   |---------------------+--------------------------------------------------|
   |  Advisory Contact   | Tilghman Lesher < tlesher AT digium DOT com >    |
   |---------------------+--------------------------------------------------|
   |      CVE Name       | CVE-2009-2726                                    |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2011-014: Remote crash possibility with SIP and the “automon” feature enabled

      Exploits Known    Yes                                                   
       Reported On      November 2, 2011                                      
       Reported By      Kristijan Vrban                                       
        Posted On       2011-11-03                                            
     Last Updated On    December 7, 2011                                      
     Advisory Contact   Terry Wilson <twilson@digium.com>                     
         CVE Name       

    Description  When the "automon" feature is enabled in features.conf, it   
                 is possible to send a sequence of SIP requests that cause    
                 Asterisk to dereference a NULL pointer and crash.            

AST-2009-001: Information leak in IAX2 authentication

   |----------------------+-------------------------------------------------|
   |      Posted On       | January 7, 2009                                 |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | January 7, 2009                                 |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Tilghman Lesher < tlesher AT digium DOT com >   |
   |----------------------+-------------------------------------------------|
   |       CVE Name       | CVE-2009-0041                                   |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2008-004: Format String Vulnerability in Logger and Manager

   |--------------------+---------------------------------------------------|
   |     Posted On      | March 18, 2008                                    |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | March 18, 2008                                    |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Joshua Colp <jcolp@digium.com>                    |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2008-1333                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2008-010: Asterisk IAX 'POKE' resource exhaustion

   |----------------------+-------------------------------------------------|
   |      Posted On       | July 22, 2008                                   |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | July 22, 2008                                   |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Tilghman Lesher < tlesher AT digium DOT com >   |
   |----------------------+-------------------------------------------------|
   |       CVE Name       | CVE-2008-3263                                   |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2009-006: IAX2 Call Number Resource Exhaustion

   |--------------------+---------------------------------------------------|
   |     Posted On      | September 3, 2009                                 |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | September 3, 2009                                 |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Russell Bryant < russell AT digium DOT com >      |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2009-2346                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

/home/putnopvut/asa/AST-2008-007/AST-2008-007: AST-2008-007 Cryptographic keys generated by OpenSSL on Debian-based systems compromised

   |--------------------+---------------------------------------------------|
   |     Posted On      | May 16, 2008                                      |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | May 22, 2008                                      |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Mark Michelson < mmichelson AT digium DOT com >   |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2008-0166                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2008-012: Remote crash vulnerability in IAX2

   |----------------------+-------------------------------------------------|
   |      Posted On       |                                                 |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | December 9, 2008                                |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Mark Michelson <mmichelson AT digium DOT com>   |
   |----------------------+-------------------------------------------------|
   |       CVE Name       |                                                 |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2009-002: Remote Crash Vulnerability in SIP channel driver

   |---------------------+--------------------------------------------------|
   |      Posted On      | March 10, 2009                                   |
   |---------------------+--------------------------------------------------|
   |   Last Updated On   | March 10, 2009                                   |
   |---------------------+--------------------------------------------------|
   |  Advisory Contact   | Joshua Colp <jcolp@digium.com>                   |
   |---------------------+--------------------------------------------------|
   |      CVE Name       |                                                  |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2007-024 - Fallacious security advisory spread on the Internet involving buffer overflow in Zaptel's sethdlc application

    |--------------------+---------------------------------------------------|
    |     Posted On      | October 31, 2007                                  |
    |--------------------+---------------------------------------------------|
    |  Last Updated On   | November 1, 2007                                  |
    |--------------------+---------------------------------------------------|
    |  Advisory Contact  | Mark Michelson <mmichelson AT digium DOT com>     |
    |--------------------+---------------------------------------------------|
    |      CVE Name      | CVE-2007-5690                                     |
    +------------------------------------------------------------------------+

    +------------------------------------------------------------------------+

AST-2011-002: Multiple array overflow and crash vulnerabilities in UDPTL code

     Exploits Known   No                                                      
      Reported On     January 27, 2011                                        
      Reported By     Matthew Nicholson                                       
       Posted On      February 21, 2011                                       
    Last Updated On   February 21, 2011                                       
    Advisory Contact  Matthew Nicholson <mnicholson@digium.com>               
        CVE Name      

   Description When decoding UDPTL packets, multiple stack and heap based     
               arrays can be made to overflow by specially crafted packets.   
               Systems doing T.38 pass through or termination are vulnerable. 

AST-2008-006 - 3-way handshake in IAX2 incomplete

   |--------------------+---------------------------------------------------|
   |     Posted On      | April 22, 2008                                    |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | April 22, 2008                                    |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Tilghman Lesher < tlesher AT digium DOT com >     |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2008-1897                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2008-008: Remote Crash Vulnerability in SIP channel driver when run in pedantic mode

   |--------------------+---------------------------------------------------|
   |     Posted On      | May 8, 2008                                       |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | June 3, 2008                                      |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Joshua Colp <jcolp@digium.com>                    |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2008-2119                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2011-006: Asterisk Manager User Shell Access

      Exploits Known    Yes                                                   
       Reported On      February 10, 2011                                     
       Reported By      Mark Murawski <markm AT intellasoft DOT net>          
        Posted On       April 21, 2011                                        
     Last Updated On    April 21, 2011                                        
     Advisory Contact   Matthew Nicholson <mnicholson@digium.com>             
         CVE Name       

   Description It is possible for a user of the Asterisk Manager Interface to 
               bypass a security check and execute shell commands when they   
               should not have that ability. Sending the "Async" header with  

AST-2009-008: SIP responses expose valid usernames

   |----------------------+-------------------------------------------------|
   |      Posted On       | November 4, 2009                                |
   |----------------------+-------------------------------------------------|
   |   Last Updated On    | November 4, 2009                                |
   |----------------------+-------------------------------------------------|
   |   Advisory Contact   | Joshua Colp <jcolp AT digium DOT com>           |
   |----------------------+-------------------------------------------------|
   |       CVE Name       |                                                 |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

AST-2011-001: Stack buffer overflow in SIP channel driver

      Exploits Known    No                                                    
       Reported On      January 11, 2011                                      
       Reported By      Matthew Nicholson                                     
        Posted On       January 18, 2011                                      
     Last Updated On    January 18, 2011                                      
     Advisory Contact   Matthew Nicholson <mnicholson@digium.com>             
         CVE Name       

   Description When forming an outgoing SIP request while in pedantic mode, a 
               stack buffer can be made to overflow if supplied with          
               carefully crafted caller ID information. This vulnerability    

AST-2007-027 - Database matching order permits host-based authentication to be ignored

   |--------------------+---------------------------------------------------|
   |     Posted On      | December 18, 2007                                 |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | December 18, 2007                                 |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Tilghman Lesher <tlesher AT digium DOT com>       |
   |--------------------+---------------------------------------------------|
   |      CVE Name      | CVE-2007-6430                                     |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

ASA-2007-019: Remote crash vulnerability in Skinny channel driver

   |--------------------+---------------------------------------------------|
   |     Posted On      | August 7, 2007                                    |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | August 7, 2007                                    |
   |--------------------+---------------------------------------------------|
   |  Advisory Contact  | Jason Parker <jparker@digium.com>                 |
   |--------------------+---------------------------------------------------|
   |      CVE Name      |                                                   |
   +------------------------------------------------------------------------+

   +------------------------------------------------------------------------+

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!