Buffer overflow in Asterisk Open Source - CVE-2012-5976

 

Buffer overflow in Asterisk Open Source - CVE-2012-5976

Published: January 4, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32727
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5976
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers to cause a denial of service (daemon crash) via TCP data using the (1) SIP, (2) HTTP, or (3) XMPP protocol.


Affected software

Asterisk Open Source
asterisk (Alpine package)
asterisk
Fedora

How to mitigate CVE-2012-5976

Install update from vendor's website.

asterisk (Alpine package) - update to 1.8.19.1-r0
asterisk - update to 1.8.20.0-1.el6

External References

Related Security Bulletins