Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-4597
Description:The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which allows remote attackers to enumerate usernames via a series of requests.
Test IDs: 1.3.6.1.4.1.25623.1.0.70595   1.3.6.1.4.1.25623.1.0.70579  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-4597
20111222 Exploit for Asterisk Security Advisory AST-2011-013
http://archives.neohapsis.com/archives/bugtraq/2011-12/0151.html
47273
http://secunia.com/advisories/47273
77597
http://osvdb.org/77597
DSA-2367
http://www.debian.org/security/2011/dsa-2367
[asterisk-dev] 20111108 Summary: SIP, NAT, security concerns, oh my!
http://lists.digium.com/pipermail/asterisk-dev/2011-November/052191.html
[oss-security] 20111209 CVE Request -- Asterisk -- AST-2011-013 and AST-2011-014
http://openwall.com/lists/oss-security/2011/12/09/3
[oss-security] 20111209 Re: CVE Request -- Asterisk -- AST-2011-013 and AST-2011-014
http://openwall.com/lists/oss-security/2011/12/09/4
http://downloads.asterisk.org/pub/security/AST-2011-013.html
http://downloads.asterisk.org/pub/security/AST-2011-013.html




© 1998-2025 E-Soft Inc. All rights reserved.