CVE-2011-2666

Publication date 6 July 2011

Last updated 24 July 2024


Ubuntu priority

Description

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.

Status

Package Ubuntu Release Status
asterisk 12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Fixed 1:1.6.2.9-2ubuntu2.1
10.10 maverick
Fixed 1:1.6.2.7-1ubuntu1.2
10.04 LTS lucid
Fixed 1:1.6.2.5-0ubuntu1.4
8.04 LTS hardy Ignored end of life


Access our resources on patching vulnerabilities