CVE-2008-3263: High severity asterisk vulnerability
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (call-number exhaustion and CPU consumption) by quickly sending a large number of IAX2 (IAX) POKE requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3263?
CVE-2008-3263 has been classified as a high severity vulnerability due to its potential to allow remote denial of service attacks.
How do I fix CVE-2008-3263?
To remediate CVE-2008-3263, update your Asterisk installation to at least version 1.2.30 or 1.4.21.2 as recommended by the vendor.
Which versions of Asterisk are affected by CVE-2008-3263?
CVE-2008-3263 affects Asterisk versions 1.0.x, 1.2.x prior to 1.2.30, and 1.4.x prior to 1.4.21.2 among others.
What type of attacks can exploit CVE-2008-3263?
CVE-2008-3263 allows remote attackers to trigger a denial of service by sending specially crafted packets.
Is there a workaround for CVE-2008-3263?
As a workaround for CVE-2008-3263, consider configuring your network firewall to limit access to the affected Asterisk server.