Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  ASTERISK : Asterisk 10.0
  ASTERISK : AsteriskNOW 1.5
  ASTERISK : Asterisk 1.8
  ASTERISK : AsteriskNOW 1.0
  ASTERISK : Asterisk 1.6
  ASTERISK : Asterisk 1,4
  ASTERISK : Asterisk s800i
  ASTERISK : Asterisk Appliance Developer Kit 0.4
  ASTERISK : Asterisk 1.3
  ASTERISK : Asterisk@Home 2.6
  ASTERISK : Asterisk 2.0
  ASTERISK : Asterisk 1.5
  ASTERISK : Asterisk 1.2
  ASTERISK : Asterisk 1.0
  ASTERISK : asterisk 0.4
Name:ASTERISK : Asterisk 1.4

 Asterisk SIP processing security vulnerabilities
updated since 11.12.2011
document DoS, information leakage.
 Asterisk user account enumeration
document Different replies on mismatched usernames and passwords.
6!Asterisk security vulnerabilities
updated since 26.04.2011
document Privilege escalation DoS via resources exhaustion.
6!Asterisk buffer overflows
document Multiple buffer overflows on UDPTL parsing.
7!Asterisk buffer overflow
document Buffer overflow in SIP Caller ID.
 Asterisk invalid ACL processing
document /0 CIDR in ACL is processed in unpredictable way.
 Asterisk dialplan modification
document Atacker can control dialplan if ${EXTEN} macro is used.
 Asterisk RTP DoS
document Crash on RTP comfort noise payload processing.
 Asterisk multiple security vulnerabilities
document Information leak, crossite scripting.
 Asterisk protection bypass
document ACL restrictions were not applied to SIP INVITE messages.
 Asterisk IAX2 DoS
document 15-bit call number resource exhaustion.
6!Asterisk SIP DoS
updated since 11.08.2009
document Stack overlow (exhaustion) on SIP request processing.
 Asterisk DoS
document Crash on RTP text frames processing.
 Asterisk VoIP server user accounts enumeration
document Different replies for non-exstant SIP account and invalid password.
 Asterisk VoIP server DoS
document NULL pointer dereference on empty SIP INVITE header.
 Asterisk user account enumeration
document Different replies for invalid username and password in IAX2 authentication.
 Asterisk voice server DoS
document Crash on IAX2 processing
 Asterisk multiple security vulnerabilities
document Traffic amplification, DoS with resouurces exhaustion.
6!Asterisk IAX2 calls spoofing
document Insuficient check of server ACK and weak call number generation allows blind spoofing.
 Asterisk SIP Also transfer DoS
document NULL pointer dereference on BYE message parsing.
6!Asterisk unauthorized access
document IP restriction is not checked for users with no password configured.
 Asterisk multiple security vulnerabilities
document cdr_pgsql and res_config_pgsql SQL injection.
 Asterisk cdr_addon_mysql SQL injection
document SQL injection with destination number.
6!Asterisk malformed MIME boundary multiple buffer overflows and DoS
updated since 27.08.2007
document Multiple buffer overflows and crash on malformed MIME boundary if IMAP storage is used for Voicemail.
 Asterisk VoIP server Skinny protocol resources aexhaustions
document SIP dialog history is stored in memory regardless of settings, leading to memory exhaustion.
 Asterisk Skinny (SIP) VoIP protocol DoS
document CAPABILITIES_RES_MESSAGE integer array overflow.
 Asterisk VoIP server IAX2 DoS
document NEW requests flood causes resources exhaustion.
7!Asterisk VoIP server multiple security vulnerabilities
document Buffer overflow and DoS on IAX2 implementation, DoS in Skinny and STUN implementation.
7!Asterisk VoIP server buffer overflow
document Multiple buffer overflows if T38 fax over SIP is enabled.
7!Asterisk multiple security vulnerabilities
document Multiple buffer overflows on T.38 SDP SIP channels parsing. DoS in administration interface. Multiple security vulnerabilities in parsing SIP replies.
6!Asterisk PBX SIP DoS
updated since 04.03.2007
document Application crash on malcrafted SIP packet.
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server