CVE-2011-2529: Buffer Overflow
chansip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2529?
CVE-2011-2529 has been classified as a denial of service vulnerability with potential memory corruption risks.
How do I fix CVE-2011-2529?
To fix CVE-2011-2529, upgrade to Asterisk version 1.6.2.18.1, 1.8.4.3, or later.
What types of systems are affected by CVE-2011-2529?
CVE-2011-2529 affects various versions of Asterisk Open Source, specifically those prior to 1.6.2.18.1 and 1.8.4.3.
Can CVE-2011-2529 lead to other impacts besides denial of service?
Yes, CVE-2011-2529 may allow remote attackers to cause unspecified impacts beyond denial of service, typically relating to memory corruption.
Is there a patch available for CVE-2011-2529?
Yes, patches addressing CVE-2011-2529 have been published and are available in updated versions of Asterisk.