CVE-2012-5976: Buffer Overflow
Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers to cause a denial of service (daemon crash) via TCP data using the (1) SIP, (2) HTTP, or (3) XMPP protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5976?
CVE-2012-5976 has a high severity rating as it allows remote attackers to cause a denial of service through multiple stack consumption vulnerabilities.
How do I fix CVE-2012-5976?
To fix CVE-2012-5976, update Asterisk to version 1.8.19.1, 10.11.1, or 11.1.2 or later.
What versions of Asterisk are affected by CVE-2012-5976?
CVE-2012-5976 affects Asterisk versions 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2.
Can CVE-2012-5976 be exploited remotely?
Yes, CVE-2012-5976 can be exploited remotely, allowing attackers to disrupt service.
What type of vulnerability is CVE-2012-5976 classified as?
CVE-2012-5976 is classified as a stack consumption vulnerability.