Remote crash possibility with SIP and the “automon” feature enabled

Home » VoIP News » Remote crash possibility with SIP and the “automon” feature enabled
VoIP News No Comments

Asterisk Project Security Advisory – AST-2011-014

Summary:      Remote crash possibility with SIP and the “automon”

Description:  When the “automon” feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash.

Resolution:    Applying the referenced patches that check that the pointer is not NULL before accessing it will resolve the issue. The
“automon” feature can be disabled in features.conf as a workaround.

Patches

Download URL Revision
http://downloads.asterisk.org/pub/security/AST-2011-014-1.6.2.diff 1.6.2.20
http://downloads.asterisk.org/pub/security/AST-2011-014-1.8.diff 1.8.7.1

Links

Asterisk Project Security Advisories are posted at
http://www.asterisk.org/security

This document may be superseded by later versions; if so, the latest version will be posted at
http://downloads.digium.com/pub/security/AST-2011-014.pdf and http://downloads.digium.com/pub/security/AST-2011-014.html