Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
21 Nov 2024, 01:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://downloads.digium.com/pub/security/AST-2011-005.html - Vendor Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058922.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059702.html - | |
References | () http://secunia.com/advisories/44197 - Vendor Advisory | |
References | () http://secunia.com/advisories/44529 - | |
References | () http://securitytracker.com/id?1025432 - | |
References | () http://www.debian.org/security/2011/dsa-2225 - | |
References | () http://www.vupen.com/english/advisories/2011/1086 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2011/1107 - | |
References | () http://www.vupen.com/english/advisories/2011/1188 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=698916 - Patch |
Information
Published : 2011-04-27 00:55
Updated : 2024-11-21 01:26
NVD link : CVE-2011-1507
Mitre link : CVE-2011-1507
CVE.ORG link : CVE-2011-1507
JSON object : View
Products Affected
digium
- asterisk
CWE
CWE-399
Resource Management Errors