CVE-2011-2216: Null Pointer Dereference
Published Jun 6, 2011
·Updated
reqrespparser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.
Affected Software
31 affected components
Asterisk=1.8.0
Asterisk=1.8.0-beta1
Asterisk=1.8.0-beta2
Asterisk=1.8.0-beta3
Asterisk=1.8.0-beta4
Asterisk=1.8.0-beta5
Asterisk=1.8.0-rc2
Asterisk=1.8.0-rc3
Asterisk=1.8.0-rc4
Asterisk=1.8.0-rc5
Asterisk=1.8.1
Asterisk=1.8.1-rc1
Asterisk=1.8.1.1
Asterisk=1.8.1.2
Asterisk=1.8.2
Asterisk=1.8.2.1
Asterisk=1.8.2.2
Asterisk=1.8.2.3
Asterisk=1.8.2.4
Asterisk=1.8.3
Asterisk=1.8.3-rc1
Asterisk=1.8.3-rc2
Asterisk=1.8.3-rc3
Asterisk=1.8.3.1
Asterisk=1.8.3.2
Asterisk=1.8.3.3
Asterisk=1.8.4
Asterisk=1.8.4-rc1
Asterisk=1.8.4-rc2
Asterisk=1.8.4-rc3
Asterisk=1.8.4.1
Event History
Jun 6, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2216?
The severity of CVE-2011-2216 is classified as a denial of service vulnerability due to a NULL pointer dereference.
2
How do I fix CVE-2011-2216?
To fix CVE-2011-2216, upgrade to Asterisk version 1.8.4.2 or later.
3
Which versions of Asterisk are affected by CVE-2011-2216?
CVE-2011-2216 affects Asterisk versions 1.8.x prior to 1.8.4.2.
4
What kind of attacks can exploit CVE-2011-2216?
CVE-2011-2216 can be exploited by remote attackers sending malformed Contact headers, causing the daemon to crash.
5
Is there a workaround for CVE-2011-2216?
Currently, the recommended action for CVE-2011-2216 is to apply the software update, as no specific workaround is provided.