bugs.digium.comConfirmation
http://bugs.digium.com/view.php?id=12607 CVE-2008-2119
Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash
Record summary
CVE-2008-2119 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAsterisk 1.2.x - SIP channel driver / in pedantic mode Remote CrashExploitDB exploitby Armando OliveiraNot analyzed1 file
References
12downloads.digium.comConfirmation
http://downloads.digium.com/pub/security/AST-2008-008.html 30517Third-party advisory
http://secunia.com/advisories/30517 34982Third-party advisory
http://secunia.com/advisories/34982 GLSA-200905-01Vendor advisory
http://security.gentoo.org/glsa/glsa-200905-01.xml svn.digium.comConfirmation
http://svn.digium.com/view/asterisk?view=rev&revision=120109 20080603 AST-2008-008: Remote Crash Vulnerability in SIP channel driver when run in pedantic modemailing list
http://www.securityfocus.com/archive/1/493020/100/0/threaded 1020166vdb entry
http://www.securitytracker.com/id?1020166 ADV-2008-1731vdb entry
http://www.vupen.com/english/advisories/2008/1731 asterisk-asturidecode-dos(42823)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42823 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2119 5749exploit
https://www.exploit-db.com/exploits/5749