Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

VOIP:ASTERISK-IAX2-DOS

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

VOIP

Keywords

Digium Asterisk Multiple Products IAX2 Handshake Denial of Service

Release Date

2010/10/01

Update Number

1784

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

VOIP: Digium Asterisk Multiple Products IAX2 Handshake Denial of Service


This signature detects attempts to exploit a known vulnerability against multiple Digium Asterisk products. A successful attack can result in a denial-of-service condition.

Extended Description

Asterisk is prone to a remote denial-of-service vulnerability caused by a flaw in the IAX2 protocol. Successful exploits result in packet-amplification attacks. Malicious users can cause Asterisk to send large numbers of UDP datagrams to arbitrary addresses, potentially denying service to both the Asterisk service and networks that may become flooded.

Affected Products

  • Asterisk 0.1.11
  • Asterisk 0.1.7
  • Asterisk 0.1.8
  • Asterisk 0.1.9
  • Asterisk 0.1.9 -1
  • Asterisk 0.2.0
  • Asterisk 0.3.0
  • Asterisk 0.4.0
  • Asterisk 0.4.1
  • Asterisk 0.7.0 .0
  • Asterisk 0.7.1
  • Asterisk 0.7.2
  • Asterisk 0.9.0 .0
  • Asterisk 1.0.0
  • Asterisk 1.0.10
  • Asterisk 1.0.11
  • Asterisk 1.0.12
  • Asterisk 1.0.3.4
  • Asterisk 1.0.6
  • Asterisk 1.0.7
  • Asterisk 1.0.8
  • Asterisk 1.0.9
  • Asterisk 1.2.0 .0-beta1
  • Asterisk 1.2.0 .0-beta2
  • Asterisk 1.2.10
  • Asterisk 1.2.11
  • Asterisk 1.2.13
  • Asterisk 1.2.14
  • Asterisk 1.2.15
  • Asterisk 1.2.16
  • Asterisk 1.2.17
  • Asterisk 1.2.18
  • Asterisk 1.2.19
  • Asterisk 1.2.21
  • Asterisk 1.2.22
  • Asterisk 1.2.23
  • Asterisk 1.2.24
  • Asterisk 1.2.25
  • Asterisk 1.2.26
  • Asterisk 1.2.27
  • Asterisk 1.2.5
  • Asterisk 1.2.6
  • Asterisk 1.2.7
  • Asterisk 1.2.8
  • Asterisk 1.2.9
  • Asterisk 1.4.1
  • Asterisk 1.4.10
  • Asterisk 1.4.11
  • Asterisk 1.4.12
  • Asterisk 1.4.13
  • Asterisk 1.4.14
  • Asterisk 1.4.15
  • Asterisk 1.4.16
  • Asterisk 1.4.17
  • Asterisk 1.4.18
  • Asterisk 1.4.18.1
  • Asterisk 1.4.19
  • Asterisk 1.4.19-Rc3
  • Asterisk 1.4.2
  • Asterisk 1.4.3
  • Asterisk 1.4.4
  • Asterisk 1.4.5
  • Asterisk 1.4.6
  • Asterisk 1.4.7
  • Asterisk 1.4.8
  • Asterisk 1.4.9
  • Asterisk 1.4 Beta
  • Asterisk 1.4 Revision 95946
  • Asterisk Asterisk Appliance Developer Kit 0.2.0
  • Asterisk Asterisk Appliance Developer Kit 0.3.0
  • Asterisk Asterisk Appliance Developer Kit 0.4.0
  • Asterisk Asterisk Appliance Developer Kit 0.5.0
  • Asterisk Asterisk Appliance Developer Kit 0.6.0
  • Asterisk Asterisk Appliance Developer Kit 0.7.0
  • Asterisk Asterisk Appliance Developer Kit 0.8.0
  • Asterisk Asterisk Appliance Developers Kit
  • Asterisk Asterisk Business Edition A
  • Asterisk Asterisk Business Edition B
  • Asterisk Asterisk Business Edition B.1.3.2
  • Asterisk Asterisk Business Edition B.1.3.3
  • Asterisk Asterisk Business Edition B.2.2.0
  • Asterisk Asterisk Business Edition B.2.2.1
  • Asterisk Asterisk Business Edition B.2.3.1
  • Asterisk Asterisk Business Edition B.2.3.2
  • Asterisk Asterisk Business Edition B.2.3.3
  • Asterisk Asterisk Business Edition B.2.3.4
  • Asterisk Asterisk Business Edition B.2.3.6
  • Asterisk Asterisk Business Edition B.2.5.1
  • Asterisk Asterisk Business Edition C
  • Asterisk Asterisk Business Edition C.1.0-beta7
  • Asterisk Asterisk Business Edition C.1.0-beta8
  • Asterisk Asterisk Business Edition C.1.6
  • Asterisk Asterisk Business Edition C.1.6.1
  • Asterisk Asterisk Business Edition C.1.6.2
  • Asterisk AsteriskNow 1.0
  • Asterisk AsteriskNow 1.0.2
  • Asterisk AsteriskNow Beta 5
  • Asterisk AsteriskNow Beta 6
  • Asterisk AsteriskNow Beta 7
  • Asterisk s800i Appliance 1.0.0
  • Asterisk s800i Appliance 1.0.1
  • Asterisk s800i Appliance 1.0.2
  • Asterisk s800i Appliance 1.0.3
  • Asterisk s800i Appliance 1.1.0.0
  • Asterisk s800i Appliance 1.1.0.2
  • Debian Linux 4.0
  • Debian Linux 4.0 Alpha
  • Debian Linux 4.0 Amd64
  • Debian Linux 4.0 Arm
  • Debian Linux 4.0 Hppa
  • Debian Linux 4.0 Ia-32
  • Debian Linux 4.0 Ia-64
  • Debian Linux 4.0 M68k
  • Debian Linux 4.0 Mips
  • Debian Linux 4.0 Mipsel
  • Debian Linux 4.0 Powerpc
  • Debian Linux 4.0 S/390
  • Debian Linux 4.0 Sparc
  • Gentoo Linux
  • Red Hat Fedora 7
  • Red Hat Fedora 8

References

  • BugTraq: 28901
  • CVE: CVE-2008-1897

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out