Buffer overflow in Asterisk Open Source - CVE-2012-5977

 

Buffer overflow in Asterisk Open Source - CVE-2012-5977

Published: January 4, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32728
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5977
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.


Affected software

Asterisk Open Source
asterisk (Alpine package)
asterisk
Fedora

How to mitigate CVE-2012-5977

Install update from vendor's website.

asterisk (Alpine package) - update to 1.8.19.1-r0
asterisk - update to 1.8.20.0-1.el6

External References

Related Security Bulletins