CVE-2012-1184: Buffer Overflow
Stack-based buffer overflow in the astparsedigest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1184?
CVE-2012-1184 has a severity rating that indicates it can lead to denial of service and potentially allow the execution of arbitrary code.
How do I fix CVE-2012-1184?
To fix CVE-2012-1184, you should upgrade Asterisk to version 1.8.10.1 or later, or to version 10.2.1 or later.
What systems are affected by CVE-2012-1184?
CVE-2012-1184 affects Asterisk versions 1.8.x prior to 1.8.10.1 and 10.x prior to 10.2.1.
What kind of attack does CVE-2012-1184 enable?
CVE-2012-1184 enables remote attackers to perform denial of service attacks or potentially execute arbitrary code via specially crafted HTTP Digest Authentication headers.
When was CVE-2012-1184 disclosed?
CVE-2012-1184 was disclosed in 2012, affecting specific versions of Asterisk.