First published: Fri Apr 22 2011(Updated: )
Asterisk did not limit the number of unauthenticated connections to vulnerable interfaces and did not limit the time unauthenticated clients remain connected to some interfaces. A remote attacker could open many subsequent connections to vulnerable Asterisk interfaces, leading to file descriptor resource exhaustion or possibly to disk space exhaustion (due Asterisk feature of logging failures to open new file descriptors into its log file). References: [1] <a href="http://downloads.asterisk.org/pub/security/AST-2011-005.html">http://downloads.asterisk.org/pub/security/AST-2011-005.html</a> Upstream patches: [2] <a href="http://downloads.asterisk.org/pub/security/AST-2011-005-1.4.diff">http://downloads.asterisk.org/pub/security/AST-2011-005-1.4.diff</a> (against v1.4 branch) [3] <a href="http://downloads.asterisk.org/pub/security/AST-2011-005-1.6.1.diff">http://downloads.asterisk.org/pub/security/AST-2011-005-1.6.1.diff</a> (against v1.6.1 branch) [4] <a href="http://downloads.asterisk.org/pub/security/AST-2011-005-1.6.2.diff">http://downloads.asterisk.org/pub/security/AST-2011-005-1.6.2.diff</a> (against v1.6.2 branch) [5] <a href="http://downloads.asterisk.org/pub/security/AST-2011-005-1.8.diff">http://downloads.asterisk.org/pub/security/AST-2011-005-1.8.diff</a> (against v1.8 branch)
Affected Software | Affected Version | How to fix |
---|---|---|
Asterisk | >1.8>1.4<=1.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-698916 addresses the lack of limits on unauthenticated connections and their duration on Asterisk interfaces.
The impact of REDHAT-BUG-698916 is that a remote attacker could open multiple connections to vulnerable interfaces, potentially exhausting file descriptors.
To mitigate risks associated with REDHAT-BUG-698916, ensure that you apply the security patches provided for the affected Asterisk versions.
Asterisk versions from 1.4 to 1.6.2 and any versions beyond 1.8 are affected by REDHAT-BUG-698916.
To secure your Asterisk installation related to REDHAT-BUG-698916, limit unauthenticated access and apply recommended security updates.