Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2536

Опубликовано: 06 июл. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests.

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

released

1:1.6.2.5-0ubuntu1.4
maverick

released

1:1.6.2.7-1ubuntu1.2
natty

released

1:1.6.2.9-2ubuntu2.1
oneiric

not-affected

1:1.8.4.4~dfsg-2ubuntu1.1
precise

not-affected

quantal

not-affected

upstream

released

1.6.2.18.2, 1.8.4.4

Показывать по

EPSS

Процентиль: 41%
0.00187
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 14 лет назад

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests.

debian
больше 14 лет назад

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x bef ...

github
больше 3 лет назад

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests.

EPSS

Процентиль: 41%
0.00187
Низкий

5 Medium

CVSS2