Digium.Asterisk.IAX2.Call.Number.DoS

Release DateDec 15, 2009
SeverityHigh
ImpactDenial of Service
DescriptionThis indicates an attack attempt against a resource-exhaustion-based denial-of-service vulnerability in Digium's Asterisk.

The vulnerability is caused by a design weakness when the vulnerable software handles a large number of messages. It allows a remote attacker to cause a denial-of-service condition.
Affected ProductsAsterisk Asterisk Business Edition C.3.1.0 and previous versions
Asterisk Asterisk 1.6.1 5 and previous versions
Recommended ActionsUpgrade to the latest versions:
http://www.asterisk.org/
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2346
Reference/shttp://www.securityfocus.com/bid/36275 (BugTraq)
http://secunia.com/advisories/36593
Reference: VID-17991