CVE-2012-5977: Buffer Overflow
Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5977?
The severity of CVE-2012-5977 is considered to be high due to its potential to cause denial of service.
How do I fix CVE-2012-5977?
To fix CVE-2012-5977, upgrade to Asterisk versions 1.8.19.1, 10.11.1, or 11.1.2 and above.
What types of systems are affected by CVE-2012-5977?
CVE-2012-5977 affects Asterisk versions prior to specific updates, including versions 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2.
What kind of exploit does CVE-2012-5977 allow?
CVE-2012-5977 allows remote attackers to cause a denial of service by exploiting anonymous call functionality.
Is there any workaround available for CVE-2012-5977?
Disabling anonymous calls can serve as a temporary workaround for CVE-2012-5977 until the system is upgraded.