CVE-2011-4598: Infoleak
The handlerequestinfo function in channels/chansip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted sequence of SIP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4598?
CVE-2011-4598 has a severity that may lead to a denial of service, causing the Asterisk service to crash.
How do I fix CVE-2011-4598?
To fix CVE-2011-4598, upgrade Asterisk to version 1.6.2.21 or 1.8.7.2 or later.
What software is affected by CVE-2011-4598?
Asterisk Open Source versions 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2 are affected by CVE-2011-4598.
Can CVE-2011-4598 be exploited remotely?
Yes, CVE-2011-4598 can be exploited by remote attackers through crafted SIP requests.
What is the impact of exploiting CVE-2011-4598?
Exploiting CVE-2011-4598 can lead to a null pointer dereference and result in a crash of the Asterisk daemon.