Buffer overflow in Asterisk Open Source - CVE-2012-5977
Published: January 4, 2013 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.
Affected software
asterisk (Alpine package)
asterisk
Fedora
How to mitigate CVE-2012-5977
asterisk - update to 1.8.20.0-1.el6