chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.conf configuration is set to a value greater than 1245, allows remote attackers to cause a denial of service (file descriptor consumption) via vectors related to large retransmit timeout values.
No CVSS v3.1
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
AV:N/AC:M/Au:N/C:N/I:N/A:C
Vendors | Products |
---|---|
Digium |
|
Fedoraproject |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
References
Link | Resource |
---|---|
http://downloads.asterisk.org/pub/security/AST-2016-002.html | Exploit Patch Vendor Advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177409.html | Third Party Advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177422.html | Third Party Advisory |
http://www.debian.org/security/2016/dsa-3700 | |
http://www.securityfocus.com/bid/82651 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1034930 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2016-02-22T15:05:00
Updated: 2017-11-03T18:57:01
Reserved: 2016-02-11T00:00:00
Link: CVE-2016-2316
JSON object: View
NVD Information
Status : Modified
Published: 2016-02-22T15:59:02.160
Modified: 2017-11-04T01:29:18.617
Link: CVE-2016-2316
JSON object: View
Redhat Information
No data.
CWE