Unrestricted Session Vulnerability in Asterisk Open Source and Business Edition

Unrestricted Session Vulnerability in Asterisk Open Source and Business Edition

CVE-2011-1507 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.

Learn more about our Open Source Audit.