Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22692
HistoryOct 28, 2009 - 12:00 a.m.

AST-2009-007: ACL not respected on SIP INVITE

2009-10-2800:00:00
vulners.com
8
           Asterisk Project Security Advisory - AST-2009-007

±-----------------------------------------------------------------------+
| Product | Asterisk |
|--------------------±--------------------------------------------------|
| Summary | ACL not respected on SIP INVITE |
|--------------------±--------------------------------------------------|
| Nature of Advisory | Unauthorized calls allowed on prohibited networks |
|--------------------±--------------------------------------------------|
| Susceptibility | Remote unauthorized session |
|--------------------±--------------------------------------------------|
| Severity | Critical |
|--------------------±--------------------------------------------------|
| Exploits Known | No |
|--------------------±--------------------------------------------------|
| Reported On | October 18, 2009 |
|--------------------±--------------------------------------------------|
| Reported By | Thomas Athineou <thom_winkler AT web DOT de> |
|--------------------±--------------------------------------------------|
| Posted On | October 26, 2009 |
|--------------------±--------------------------------------------------|
| Last Updated On | October 26, 2009 |
|--------------------±--------------------------------------------------|
| Advisory Contact | Jeff Peeler <jpeeler AT digium DOT com> |
|--------------------±--------------------------------------------------|
| CVE Name | |
±-----------------------------------------------------------------------+

±-----------------------------------------------------------------------+
| Description | A missing ACL check for handling SIP INVITEs allows a |
| | device to make calls on networks intended to be |
| | prohibited as defined by the "deny" and "permit" lines |
| | in sip.conf. The ACL check for handling SIP |
| | registrations was not affected. |
±-----------------------------------------------------------------------+

±-----------------------------------------------------------------------+
| Resolution | Users should upgrade to a version listed in the |
| | "Corrected In" section below. |
±-----------------------------------------------------------------------+

±-----------------------------------------------------------------------+

Affected Versions
Product
-------------------------------±---------------±----------------------
Asterisk Open Source
-------------------------------±---------------±----------------------
Asterisk Open Source
-------------------------------±---------------±----------------------
Asterisk Open Source
-------------------------------±---------------±----------------------
Asterisk Addons
-------------------------------±---------------±----------------------
Asterisk Addons
-------------------------------±---------------±----------------------
Asterisk Addons
-------------------------------±---------------±----------------------
Asterisk Business Edition
-------------------------------±---------------±----------------------
Asterisk Business Edition
-------------------------------±---------------±----------------------
Asterisk Business Edition
-------------------------------±---------------±----------------------
AsteriskNOW
-------------------------------±---------------±----------------------
s800i (Asterisk Appliance)
±-----------------------------------------------------------------------+

±-----------------------------------------------------------------------+

Corrected In
Product
---------------------------------------------±-------------------------
Open Source Asterisk 1.6.1
±-----------------------------------------------------------------------+

±---------------------------------------------------------------------------+

Patches
SVN URL
--------------------------------------------------------------------±------
http://downloads.digium.com/pub/security/AST-2009-007-1.6.1.diff.txt
±---------------------------------------------------------------------------+

±-----------------------------------------------------------------------+
| Links | |
±-----------------------------------------------------------------------+

±-----------------------------------------------------------------------+
| Asterisk Project Security Advisories are posted at |
| http://www.asterisk.org/security |
| |
| This document may be superseded by later versions; if so, the latest |
| version will be posted at |
| http://downloads.digium.com/pub/security/AST-2009-007.pdf and |
| http://downloads.digium.com/pub/security/AST-2009-007.html |
±-----------------------------------------------------------------------+

±-----------------------------------------------------------------------+

Revision History
Date
------------------------±-----------------±---------------------------
October 26, 2009
±-----------------------------------------------------------------------+
           Asterisk Project Security Advisory - AST-2009-007
          Copyright &#40;c&#41; 2009 Digium, Inc. All Rights Reserved.

Permission is hereby granted to distribute and publish this advisory in its
original, unaltered form.