Rapid7 Vulnerability & Exploit Database

Alpine Linux: CVE-2012-2416: Multiple vulnerabilties in asterisk < 1.8.12.1 may allow remote code execution

Back to Search

Alpine Linux: CVE-2012-2416: Multiple vulnerabilties in asterisk < 1.8.12.1 may allow remote code execution

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
04/30/2012
Created
07/25/2018
Added
09/20/2017
Modified
05/09/2019

Description

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid option is enabled, allows remote authenticated users to cause a denial of service (daemon crash) by sending a SIP UPDATE message that triggers a connected-line update attempt without an associated channel.

Solution(s)

  • alpine-linux-upgrade-asterisk

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;