Remote crash possibility with SIP and the “automon” feature enabled
Asterisk Project Security Advisory – AST-2011-014
Summary: Remote crash possibility with SIP and the “automon”
Description: When the “automon” feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash.
Resolution: Applying the referenced patches that check that the pointer is not NULL before accessing it will resolve the issue. The
“automon” feature can be disabled in features.conf as a workaround.
Patches
Download URL Revision
http://downloads.asterisk.org/pub/security/AST-2011-014-1.6.2.diff 1.6.2.20
http://downloads.asterisk.org/pub/security/AST-2011-014-1.8.diff 1.8.7.1
Links
Asterisk Project Security Advisories are posted at
http://www.asterisk.org/security
This document may be superseded by later versions; if so, the latest version will be posted at
http://downloads.digium.com/pub/security/AST-2011-014.pdf and http://downloads.digium.com/pub/security/AST-2011-014.html