This application requires Javascript for optimal performance.

Asterisk.T.38.Remote.Buffer.Overflow

Release Date

Dec 24, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a Remote Code Execution vulnerability in Asterisk.

The vulnerability is caused by a stack-based buffer overflow in the process_sdp function in chan_sip.c. It allows remote attackers to execute arbitrary code.

Affected Products

Asterisk AsteriskNow Beta 5
Asterisk Asterisk 1.4.2
Asterisk Asterisk 1.4.1
Asterisk Asterisk 1.4 Beta
Asterisk Appliance Developers Kit 0.3

Recommended Actions

Apply the patch, available from the following web sites:

Asterisk Asterisk 1.4 Beta
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.4.3.tar.gz

Asterisk Asterisk 1.4.1
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.4.3.tar.gz

Asterisk Asterisk 1.4.2
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.4.3.tar.gz

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-2293

Reference/s

http://www.securityfocus.com/bid/23648 (BugTraq)
http://www.securityfocus.com/archive/1/archive/1/466883/100/0/threaded

Reference: VID-30420