Vulnerabilities > Digium > Asterisk > 1.6.1.24

DATE CVE VULNERABILITY TITLE RISK
2011-07-06 CVE-2011-2529 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Digium Asterisk
chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.
network
low complexity
digium CWE-119
5.0
2011-04-27 CVE-2011-1599 Improper Input Validation vulnerability in Digium Asterisk
manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system privilege, which allows remote authenticated users to execute arbitrary commands via an Originate action that has an Async header in conjunction with an Application header.
network
low complexity
digium CWE-20
critical
9.0
2011-04-27 CVE-2011-1507 Resource Management Errors vulnerability in Digium Asterisk
Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.
network
low complexity
digium CWE-399
5.0