VOIP: Digium Asterisk Multiple Products IAX2 Handshake Denial of Service

This signature detects attempts to exploit a known vulnerability against multiple Digium Asterisk products. A successful attack can result in a denial-of-service condition.

Extended Description

Asterisk is prone to a remote denial-of-service vulnerability caused by a flaw in the IAX2 protocol. Successful exploits result in packet-amplification attacks. Malicious users can cause Asterisk to send large numbers of UDP datagrams to arbitrary addresses, potentially denying service to both the Asterisk service and networks that may become flooded.

Affected Products

Asterisk asterisk_business_edition,Asterisk asterisk

References

BugTraq: 28901

CVE: CVE-2008-1897

Short Name
VOIP:ASTERISK-IAX2-DOS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
VOIP
Keywords
Asterisk CVE-2008-1897 Denial Digium Handshake IAX2 Multiple Products Service bid:28901 of
Release Date
10/01/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
UDP/4569
False Positive
Unknown
Vendors

Red_hat

Asterisk

Debian

Gentoo

CVSS Score

4.3

Found a potential security threat?