The SIP channel driver in Asterisk Open Source 1.2.x before...
Vulnerability Description
The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2726
Credits & Attribution
No credits recorded in the NVD database.
References
- http://labs.mudynamics.com/advisories/MU-200908-01.txt
- http://www.vupen.com/english/advisories/2009/2229
- http://downloads.digium.com/pub/security/AST-2009-005.html
- http://www.securityfocus.com/bid/36015
- http://www.securityfocus.com/archive/1/505669/100/0/threaded
- http://www.securitytracker.com/id?1022705
- http://secunia.com/advisories/36227
More from digium
View All →Affected Vendor
digium
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.