Asterisk Vulnerability Discovered

Source: asteriskblog.com

man hitting computer

Here is something for all Asterisk users out there.  Though we may all be very enthusiastic about Asterisk and the service it provides, we have to be practical and keep our eyes open for vulnerabilities.  Even the people over at Digium do not act like ostriches and keep their head buried in the sand – I guess most other service providers act the same way.  They are always on the look out for weaknesses that other unscrupulous individuals may take advantage of.

Recently, Joel R. Voss aka. Javantea reported a vulnerability in Asterisk systems that may result in denial of service.  Many other sites and blogs have subsequently spread the word about the possible problems that may arise from the vulnerability.  People over at Digium themselves have released an advisory about the issue.  They have also released work arounds that could help solve the issue and avoid potential problems that may arise from it.

Below is the description of the vulnerability as well as other important details that you may need to resolve the issue.  This was taken from Secunia:

Description:
A vulnerability has been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to improper verification of ACK responses during IAX2 handshakes, which can be exploited to spoof an IAX2 handshake and cause a DoS via high bandwidth usage.

The vulnerability is reported in the following versions:
* Asterisk Open Source 1.0.x (all versions)
* Asterisk Open Source 1.2.x (all versions prior to 1.2.28)
* Asterisk Open Source 1.4.x (all versions prior to 1.4.19.1)
* Asterisk Business Edition A.x.x (all versions)
* Asterisk Business Edition B.x.x (all versions prior to B.2.5.2)
* Asterisk Business Edition C.x.x (all versions prior to C.1.8.1)
* AsteriskNOW 1.0.x (all versions prior to 1.0.3)
* Asterisk Appliance Developer Kit 0.x.x (all versions)
* s800i (Asterisk Appliance) 1.0.x (all versions prior to 1.1.0.3)

Solution:
Asterisk Open Source 1.2.x:
Fixed in 1.2.28.

Asterisk Open Source 1.4.x:
Fixed in 1.4.19.1.

Asterisk Business Edition B.x.x:
Fixed in B.2.5.2

Asterisk Business Edition C.x.x:
Fixed in C.1.8.1.

AsteriskNOW:
Fixed in 1.0.3.

s800i (Asterisk Appliance):
Fixed in 1.1.0.3.

Provided and/or discovered by:
Joel R. Voss a.k.a. Javantea

Original Advisory:
Asterisk:
http://downloads.digium.com/pub/security/AST-2008-006.html

AltSci:
https://www.altsci.com/concepts/page.php?s=asteri&p=2

Here’s to hoping that you will be able to take care of the vulnerability before anything adverse happens!

Published on April 23rd, 2008 under , ,


Last 20 posts tagged "VoIP"

Germans Doesn’t Like iPhone VoIP

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

In Germany, the T-Mobile, a big multinational company related to mobile network, seems have some annoyance for the use of VoIP over the iPhone, precisely wit…

Published on July 18th, 2008 under , , , ,

Also Fring Prepare VoIP For The iPhone

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

Even if in pre-release version, the popular Fring it’s ready to land on the iPhone, Fring is a instant messaging software dedicated to mobile phones, smartphones,…

Published on July 16th, 2008 under , , ,

Truphone, VoIP on iPhone Comes First Than iCall

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

Truphone, a free application formerly known to make low-cost VoIP calls by the latest Nokia cellphones, it’s ready also for the newest by Apple, the iPhone,…

Published on July 16th, 2008 under , , , ,

The Threat Poses by VoIP Spam

Source: solokay.blogspot.com

People no longer have absolute trust in using email because of fear of infiltration by spammers who are always ready to use any means to obtain sensitive information in order to swindle t…

Published on July 16th, 2008 under , , ,

VoIP Logic Announces New Billing System

Source: solokay.blogspot.com

Introducing a new Wholesale Billing module for its award-winning Cortex © middleware, VoIP Logic, one of the leading global providers of VoIP Managed Services and solutions announced that…

Published on July 16th, 2008 under , , , ,

TRUPHONE’S voIP App Available for iPhone

Source: solokay.blogspot.com

The VoIP application manufacturer, Truphone has released the iPhone version of its application for iPhone users. With this new application, users of iPhone can now send text messages or mak…

Published on July 15th, 2008 under , , , ,

Cell phones and VoIP are becoming more Popular than Landlines in Europe

Source: solokay.blogspot.com

A recent survey carried out in Europe revealed that European households are replacing the use of landline with either cell phones or VoIP; some even adopt both the mobile phones and VoIP internet…

Published on July 15th, 2008 under , , , , , ,

Cisco patches potentially crippling VoIP flaws

Source: solokay.blogspot.com

The bugs – rated "highly critical" by vulnerability tracking firm Secunia – were reported in 16 devices from the networking giant’s Unified IP Phone 7900 series, according…

Published on July 11th, 2008 under , , ,

Citrus Introduces DIGITALK VoIP platform

Source: solokay.blogspot.com

One of the UK’s most innovative communications providers, Citrus Telecom, has expanded its range of VoIP services for its residential and business markets. Citrus deployed DIGITALK Broadband…

Published on July 10th, 2008 under , , , , , , ,

iCall, iPhone, it’s VoIP

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

Even the iPhone will have its special VoIP application, the software it’s still in development and it will be released for sale or for free in the App Store,…

Published on July 4th, 2008 under , ,

How To Intercept VoIP Calls

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

On the italian website ZeusNews.it there’s an article that explain, sketchily, a way to intercept VoIP calls without breaking the cryptographic system but…

Published on June 30th, 2008 under , ,

3CX Releases VoIP PBX Software

Source: solokay.blogspot.com

A new software-based VoIP PBX which replaces traditional proprietary hardware PBX / PABX has been launched by 3CX, and this new software is the version 6.0 of 3CX phone system that works perfectly…

Published on June 29th, 2008 under , , , , ,

VoipWise

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

Born a "new" software for VoIP calls and free SMS sending very but very similar to the other ones I spoke about in an old little article.
Reading from…

Published on June 27th, 2008 under , , , , ,

Verizon Announces Expansion of VoIP Services in Europe

Source: solokay.blogspot.com

With the quest for VoIP companies to promote "advance global collaboration", Verizon has decided to expand its unified communications and VoIP services to some European markets.
Wit…

Published on June 27th, 2008 under , , , , , , , ,

New VoIP Application for Apple iPhone

Source: solokay.blogspot.com

A new VoIP application for iPhone that have been upgraded to the latest firmware supporting 3rd party applications will soon be made available. This new application, called iCall will hopefully…

Published on June 27th, 2008 under , , , , ,

Compression Techniques, a Potential Threat to VoIP Security

Source: solokay.blogspot.com

Recently at the Johns Hopkins University, Baltimore, a group of researchers announced that there is a looming security breach that is threatening the VoIP market. This was published in a paper…

Published on June 26th, 2008 under , , , , ,

Skype Launches New VoIP Platform

Source: solokay.blogspot.com

Packed with video, ease of use and call quality enhancements that let users move easily from PC-to-PC audio, video and instant messaging calls, the new VoIP platform released by Skype is…

Published on June 25th, 2008 under , , , , ,

Skype™ 4 Beta

Source: voip-tech.blogspot.com

Source: voip-tech.blogspot.com

Starting from the last 18th of June it’s available the version 4 beta (4.0.0.145) of the famous software Skype™. The new version apperars completely rebuild…

Published on June 23rd, 2008 under , ,

VoIP calls over GSM Offered by Truphone

Source: solokay.blogspot.com

Truphone has successfully broken into the GSM arena with their latest "TruPhone Anywhere" launch. Truphone Anywhere gives users access to their Truphone minutes from the cellular…

Published on June 20th, 2008 under , , , , , , ,

Telanetix Expands VoIP Presence

Source: solokay.blogspot.com

Telanetix, Inc., a leading IP solutions provider offering telepresence and VoIP services to the SMB and SME markets, has signed an agreement with the nation’s largest sales lead captur…

Published on June 20th, 2008 under , , , ,
Member of "Hype Media! Network"