Buffer overflow in Asterisk Open Source - CVE-2012-2416

 

Buffer overflow in Asterisk Open Source - CVE-2012-2416

Published: April 30, 2012 / Updated: July 28, 2020


Vulnerability identifier: #VU32791
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2416
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid option is enabled, allows remote authenticated users to cause a denial of service (daemon crash) by sending a SIP UPDATE message that triggers a connected-line update attempt without an associated channel.


Affected software

Asterisk Open Source
asterisk (Alpine package)

How to mitigate CVE-2012-2416

Install update from vendor's website.

Asterisk Open Source - update to 10.3.1
asterisk (Alpine package) - update to 1.8.13.0-r0

External References

Related Security Bulletins