FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-2216

This CVE name corresponds to:

Entered Topic
2011-06-02 asterisk -- Remote crash vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-2216
Phase Assigned(20110531)

Description

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.

References

Source Reference
BUGTRAQ 20110602 AST-2011-007
CONFIRM http://downloads.digium.com/pub/security/AST-2011-007.html
FEDORA FEDORA-2011-8319
FEDORA FEDORA-2011-8983
BID 48096
OSVDB 72752
SECTRACK 1025598
SECUNIA 44828
XF asterisk-parseurifull-dos(67812)