CVE-2011-2536

Publication date 6 July 2011

Last updated 24 July 2024


Ubuntu priority

Description

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests.

Status

Package Ubuntu Release Status
asterisk 12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Fixed 1:1.6.2.9-2ubuntu2.1
10.10 maverick
Fixed 1:1.6.2.7-1ubuntu1.2
10.04 LTS lucid
Fixed 1:1.6.2.5-0ubuntu1.4
8.04 LTS hardy Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
asterisk

Access our resources on patching vulnerabilities