CVE-2016-7551: High severity asterisk vulnerability
chainsip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).
Other sources
The following flaw was found in Asterisk:
The overlap dialing feature in chansip allows chansip to report to a device that the number that has been dialed is incomplete and more digits are required. If this functionality is used with a device that has performed username/password authentication RTP resources are leaked. This occurs because the code fails to release the old RTP resources before allocating new ones in this scenario. If all resources are used then RTP port exhaustion will occur and no RTP sessions are able to be set up.
Upstream bug:
https://issues.asterisk.org/jira/browse/ASTERISK-26272
External References:
http://downloads.asterisk.org/pub/security/AST-2016-007.html
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7551?
CVE-2016-7551 has a severity rating that indicates it can lead to a denial of service through port exhaustion.
How do I fix CVE-2016-7551?
To fix CVE-2016-7551, upgrade to Asterisk version 11.23.1 or 13.11.1 or later.
What systems are affected by CVE-2016-7551?
CVE-2016-7551 affects Asterisk versions prior to 11.23.1 and 13.11.1.
Is there a risk of exploitation with CVE-2016-7551?
Yes, CVE-2016-7551 allows remote attackers to exploit the vulnerability for a denial of service.
What kind of attacks can be executed using CVE-2016-7551?
Attackers can cause a denial of service by exhausting available ports, which impacts system availability.