CVE-2011-2535: Input Validation
chaniax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before C.3.7.3, accesses a memory address contained in an option control frame, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted frame.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2535?
CVE-2011-2535 is classified as a high severity vulnerability due to its potential to cause denial of service attacks.
How do I fix CVE-2011-2535?
To fix CVE-2011-2535, upgrade to Asterisk versions 1.4.41.1, 1.6.2.18.1, or 1.8.4.3 or later.
What systems are affected by CVE-2011-2535?
CVE-2011-2535 affects Asterisk Open Source versions 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3.
Can CVE-2011-2535 be exploited remotely?
Yes, CVE-2011-2535 can be exploited by remote attackers to cause denial of service.
What happens if CVE-2011-2535 is exploited?
If exploited, CVE-2011-2535 can lead to a denial of service, potentially disrupting the affected system's functionality.