Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2666

Опубликовано: 06 июл. 2011
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

released

1:1.6.2.5-0ubuntu1.4
maverick

released

1:1.6.2.7-1ubuntu1.2
natty

released

1:1.6.2.9-2ubuntu2.1
oneiric

not-affected

1:1.8.4.4~dfsg-2ubuntu1.1
precise

not-affected

quantal

not-affected

upstream

needs-triage

Показывать по

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 14 лет назад

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.

debian
больше 14 лет назад

The default configuration of the SIP channel driver in Asterisk Open S ...

github
больше 3 лет назад

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.

5 Medium

CVSS2