Asterisk SIP channel driver security bypass
| asterisk-sip-security-bypass (41308) |
Description:
Asterisk could allow a remote attacker to bypass security restrictions, caused by an error in the SIP channel driver when verifiying authentication requirements. By sending a specially-crafted "From" header to the driver, a remote attacker could exploit this vulnerability to perform unauthenticated phone calls.
Platforms Affected:
- Debian, Debian Linux 4.0
- Digium, Asterisk Appliance Developer Kit SVN pr1.4 rev.109393
- Digium, Asterisk Business Edition A.x.x
- Digium, Asterisk Business Edition B.x.x pr to B.2.5.1
- Digium, Asterisk Business Edition C.x.x pr to C.1.6.2
- Digium, Asterisk Open Source 1.0.0
- Digium, Asterisk Open Source 1.2.x prior to1.2.27
- Digium, Asterisk Open Source 1.4.x prior to 1.4.18.1
- Digium, Asterisk Open Source 1.4.x prior to 1.4.19-rc3
- Digium, AsteriskNOW 1.0.x prior to 1.0.2
- Digium, s800i 1.0.x prior to 1.1.0.2
- Gentoo, Linux
Remedy:
Refer to AST-2008-003 for patch, upgrade or suggested workaround information. See References.
Consequences:
Bypass Security
References:
- AST-2008-003, Unauthenticated calls allowed from SIP channel driver at http://downloads.digium.com/pub/security/AST-2008-003.html.
- BID-28310: Asterisk Call Authentication Security Bypass Vulnerability
- CVE-2008-1332: Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 revision 109393; and s800i 1.0.x before 1.1.0.2; allows remote attackers to access the SIP channel driver via a crafted From header.
- DSA-1525: asterisk -- several vulnerabilities
- FrSIRT/ADV-2008-0928: Asterisk Products Buffer Overflow and Security Bypass Vulnerabilities
- GLSA-200804-13: Asterisk: Multiple vulnerabilities
- SA29426: Asterisk Multiple Vulnerabilities
- SECTRACK ID: 1019629: Asterisk SIP Channel Driver Lets Remote Users Make Unauthenticated Calls
- SUSE-SR:2008:010: SUSE Security Summary Report
Reported:
Mar 18, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
