CVE-2011-4597: Infoleak
The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which allows remote attackers to enumerate usernames via a series of requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4597?
CVE-2011-4597 has been classified as a high severity vulnerability allowing username enumeration through its SIP over UDP implementation.
How do I fix CVE-2011-4597?
To mitigate CVE-2011-4597, upgrade to Asterisk versions 1.4.43, 1.6.2.21, or 1.8.7.2 or later.
What systems are affected by CVE-2011-4597?
CVE-2011-4597 affects Asterisk Open Source versions 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2.
What type of attack does CVE-2011-4597 allow?
CVE-2011-4597 enables remote attackers to enumerate valid SIP usernames by sending invalid requests.
Can CVE-2011-4597 impact secure communication?
Yes, CVE-2011-4597 can compromise the security of communication systems utilizing Asterisk by exposing valid usernames.