Vulnerabilities > CVE-2016-2232 - Unspecified vulnerability in Digium Asterisk and Certified Asterisk

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
digium
nessus

Summary

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a zero length error correcting redundancy packet for a UDPTL FAX packet that is lost.

Vulnerable Configurations

Part Description Count
Application
Digium
288

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_559F3D1BCB1D11E580A4001999F8D30B.NASL
    descriptionThe Asterisk project reports : AST-2016-001 - BEAST vulnerability in HTTP server AST-2016-002 - File descriptor exhaustion in chan_sip AST-2016-003 - Remote crash vulnerability when receiving UDPTL FAX data
    last seen2020-06-01
    modified2020-06-02
    plugin id88584
    published2016-02-05
    reporterThis script is Copyright (C) 2016-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/88584
    titleFreeBSD : asterisk -- Multiple vulnerabilities (559f3d1b-cb1d-11e5-80a4-001999f8d30b) (BEAST)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-3700.NASL
    descriptionMultiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service or incorrect certificate validation.
    last seen2020-06-01
    modified2020-06-02
    plugin id94259
    published2016-10-26
    reporterThis script is Copyright (C) 2016-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/94259
    titleDebian DSA-3700-1 : asterisk - security update