Short Name |
VOIP:ASTERISK-IAX2-DOS |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
VOIP |
Keywords |
Digium Asterisk Multiple Products IAX2 Handshake Denial of Service |
Release Date |
2010/10/01 |
Update Number |
1784 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against multiple Digium Asterisk products. A successful attack can result in a denial-of-service condition.
Asterisk is prone to a remote denial-of-service vulnerability caused by a flaw in the IAX2 protocol. Successful exploits result in packet-amplification attacks. Malicious users can cause Asterisk to send large numbers of UDP datagrams to arbitrary addresses, potentially denying service to both the Asterisk service and networks that may become flooded.