CVE-2011-1174: Medium severity asterisk vulnerability
AST-2011-003 [1] describes a resrouce exhaustion flaw in the Asterisk Manager Interface. If manger connections were rapily opened, sent invalid data, then closed, it could cause Asterisk to exhaust available CPU and memory resources. The Manager Interface is disabled by default. Versions 1.6.2.x and 1.8.x are affected, and 1.6.2.17.1 and 1.8.3.1 have been released to correct this flaw.
[1] http://downloads.asterisk.org/pub/security/AST-2011-003.pdf
Other sources
manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a series of manager sessions involving invalid data.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1174?
CVE-2011-1174 is classified as a moderate severity vulnerability due to its potential for resource exhaustion.
How do I fix CVE-2011-1174?
To fix CVE-2011-1174, ensure that the Asterisk Manager Interface is disabled if not in use and consider updating to a patched version of Asterisk.
What software is affected by CVE-2011-1174?
CVE-2011-1174 affects several versions of the Asterisk software, specifically within the 1.6.1.x and 1.6.2.x series.
What can happen if my system is vulnerable to CVE-2011-1174?
If exploited, CVE-2011-1174 can lead to potential denial of service as it can exhaust CPU and memory resources.
Is the Asterisk Manager Interface enabled by default in relation to CVE-2011-1174?
No, the Asterisk Manager Interface is disabled by default, which mitigates immediate risk for CVE-2011-1174.