Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-0495
Description:Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.
Test IDs: 1.3.6.1.4.1.25623.1.0.68916   1.3.6.1.4.1.25623.1.0.862836   1.3.6.1.4.1.25623.1.0.862835   1.3.6.1.4.1.25623.1.0.68917   1.3.6.1.4.1.25623.1.0.69105   1.3.6.1.4.1.25623.1.0.68814  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-0495
BugTraq ID: 45839
http://www.securityfocus.com/bid/45839
Bugtraq: 20110118 AST-2011-001: Stack buffer overflow in SIP channel driver (Google Search)
http://www.securityfocus.com/archive/1/515781/100/0/threaded
Debian Security Information: DSA-2171 (Google Search)
http://www.debian.org/security/2011/dsa-2171
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053689.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053713.html
http://downloads.asterisk.org/pub/security/AST-2011-001-1.6.2.diff
http://osvdb.org/70518
http://secunia.com/advisories/42935
http://secunia.com/advisories/43119
http://secunia.com/advisories/43373
http://www.vupen.com/english/advisories/2011/0159
http://www.vupen.com/english/advisories/2011/0281
http://www.vupen.com/english/advisories/2011/0449
XForce ISS Database: asterisk-asturiencode-bo(64831)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64831




© 1998-2025 E-Soft Inc. All rights reserved.