CVE Vulnerabilities

CVE-2008-1897

Improper Authentication

Published: Apr 23, 2008 | Modified: Oct 20, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the servers reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Asterisk_appliance_developer_kit Asterisk 0.2 (including) 0.2 (including)
Asterisk_appliance_developer_kit Asterisk 0.3 (including) 0.3 (including)
Asterisk_appliance_developer_kit Asterisk 0.4 (including) 0.4 (including)
Asterisk_appliance_developer_kit Asterisk 0.5 (including) 0.5 (including)
Asterisk_appliance_developer_kit Asterisk 0.6 (including) 0.6 (including)
Asterisk_appliance_developer_kit Asterisk 0.6.0 (including) 0.6.0 (including)
Asterisk_appliance_developer_kit Asterisk 0.7 (including) 0.7 (including)
Asterisk_appliance_developer_kit Asterisk 0.8 (including) 0.8 (including)
Asterisk_business_edition Asterisk * b.2.5.1 (including)
Asterisk_business_edition Asterisk * c1.8.0 (including)
Asterisk_business_edition Asterisk a (including) a (including)
Asterisk_business_edition Asterisk b.1.3.2 (including) b.1.3.2 (including)
Asterisk_business_edition Asterisk b.1.3.3 (including) b.1.3.3 (including)
Asterisk_business_edition Asterisk b.2.2.0 (including) b.2.2.0 (including)
Asterisk_business_edition Asterisk b.2.2.1 (including) b.2.2.1 (including)
Asterisk_business_edition Asterisk b.2.3.1 (including) b.2.3.1 (including)
Asterisk_business_edition Asterisk b.2.3.2 (including) b.2.3.2 (including)
Asterisk_business_edition Asterisk b.2.3.3 (including) b.2.3.3 (including)
Asterisk_business_edition Asterisk b.2.3.4 (including) b.2.3.4 (including)
Asterisk_business_edition Asterisk b.2.3.6 (including) b.2.3.6 (including)
Asterisk_business_edition Asterisk b.2.5.0 (including) b.2.5.0 (including)
Asterisk_business_edition Asterisk c.1.0-beta7 (including) c.1.0-beta7 (including)
Asterisk_business_edition Asterisk c.1.0-beta8 (including) c.1.0-beta8 (including)
Asterisk_business_edition Asterisk c.1.6 (including) c.1.6 (including)
Asterisk_business_edition Asterisk c.1.6.1 (including) c.1.6.1 (including)
Asterisk_business_edition Asterisk c.1.6.2 (including) c.1.6.2 (including)
Asterisknow Asterisk * 1.0.2 (including)
Asterisknow Asterisk 1.0 (including) 1.0 (including)
Asterisknow Asterisk 1.0.1 (including) 1.0.1 (including)
Open_source Asterisk * 1.2.27 (including)
Open_source Asterisk * 1.4.19 (including)
Open_source Asterisk 1.0 (including) 1.0 (including)
Open_source Asterisk 1.0-rc1 (including) 1.0-rc1 (including)
Open_source Asterisk 1.0-rc2 (including) 1.0-rc2 (including)
Open_source Asterisk 1.0.0 (including) 1.0.0 (including)
Open_source Asterisk 1.0.1 (including) 1.0.1 (including)
Open_source Asterisk 1.0.2 (including) 1.0.2 (including)
Open_source Asterisk 1.0.3 (including) 1.0.3 (including)
Open_source Asterisk 1.0.3.4 (including) 1.0.3.4 (including)
Open_source Asterisk 1.0.4 (including) 1.0.4 (including)
Open_source Asterisk 1.0.5 (including) 1.0.5 (including)
Open_source Asterisk 1.0.6 (including) 1.0.6 (including)
Open_source Asterisk 1.0.7 (including) 1.0.7 (including)
Open_source Asterisk 1.0.8 (including) 1.0.8 (including)
Open_source Asterisk 1.0.9 (including) 1.0.9 (including)
Open_source Asterisk 1.0.11 (including) 1.0.11 (including)
Open_source Asterisk 1.0.11-patch (including) 1.0.11-patch (including)
Open_source Asterisk 1.0.11.1 (including) 1.0.11.1 (including)
Open_source Asterisk 1.0.11.1-patch (including) 1.0.11.1-patch (including)
Open_source Asterisk 1.0.12 (including) 1.0.12 (including)
Open_source Asterisk 1.0.12-patch (including) 1.0.12-patch (including)
Open_source Asterisk 1.2.0 (including) 1.2.0 (including)
Open_source Asterisk 1.2.0-beta1 (including) 1.2.0-beta1 (including)
Open_source Asterisk 1.2.0-beta2 (including) 1.2.0-beta2 (including)
Open_source Asterisk 1.2.0-rc1 (including) 1.2.0-rc1 (including)
Open_source Asterisk 1.2.0-rc2 (including) 1.2.0-rc2 (including)
Open_source Asterisk 1.2.1 (including) 1.2.1 (including)
Open_source Asterisk 1.2.2 (including) 1.2.2 (including)
Open_source Asterisk 1.2.2-netsec (including) 1.2.2-netsec (including)
Open_source Asterisk 1.2.3 (including) 1.2.3 (including)
Open_source Asterisk 1.2.3-netsec (including) 1.2.3-netsec (including)
Open_source Asterisk 1.2.4 (including) 1.2.4 (including)
Open_source Asterisk 1.2.4-netsec (including) 1.2.4-netsec (including)
Open_source Asterisk 1.2.5 (including) 1.2.5 (including)
Open_source Asterisk 1.2.5-netsec (including) 1.2.5-netsec (including)
Open_source Asterisk 1.2.6 (including) 1.2.6 (including)
Open_source Asterisk 1.2.6-netsec (including) 1.2.6-netsec (including)
Open_source Asterisk 1.2.7 (including) 1.2.7 (including)
Open_source Asterisk 1.2.7-netsec (including) 1.2.7-netsec (including)
Open_source Asterisk 1.2.7.1 (including) 1.2.7.1 (including)
Open_source Asterisk 1.2.7.1-netsec (including) 1.2.7.1-netsec (including)
Open_source Asterisk 1.2.8 (including) 1.2.8 (including)
Open_source Asterisk 1.2.8-netsec (including) 1.2.8-netsec (including)
Open_source Asterisk 1.2.9 (including) 1.2.9 (including)
Open_source Asterisk 1.2.9.1 (including) 1.2.9.1 (including)
Open_source Asterisk 1.2.9.1-netsec (including) 1.2.9.1-netsec (including)
Open_source Asterisk 1.2.10 (including) 1.2.10 (including)
Open_source Asterisk 1.2.10-netsec (including) 1.2.10-netsec (including)
Open_source Asterisk 1.2.11 (including) 1.2.11 (including)
Open_source Asterisk 1.2.11-netsec (including) 1.2.11-netsec (including)
Open_source Asterisk 1.2.12 (including) 1.2.12 (including)
Open_source Asterisk 1.2.12-netsec (including) 1.2.12-netsec (including)
Open_source Asterisk 1.2.12.1 (including) 1.2.12.1 (including)
Open_source Asterisk 1.2.12.1-netsec (including) 1.2.12.1-netsec (including)
Open_source Asterisk 1.2.13 (including) 1.2.13 (including)
Open_source Asterisk 1.2.13-netsec (including) 1.2.13-netsec (including)
Open_source Asterisk 1.2.14 (including) 1.2.14 (including)
Open_source Asterisk 1.2.14-netsec (including) 1.2.14-netsec (including)
Open_source Asterisk 1.2.15 (including) 1.2.15 (including)
Open_source Asterisk 1.2.15-netsec (including) 1.2.15-netsec (including)
Open_source Asterisk 1.2.16 (including) 1.2.16 (including)
Open_source Asterisk 1.2.16-netsec (including) 1.2.16-netsec (including)
Open_source Asterisk 1.2.17 (including) 1.2.17 (including)
Open_source Asterisk 1.2.17-netsec (including) 1.2.17-netsec (including)
Open_source Asterisk 1.2.18 (including) 1.2.18 (including)
Open_source Asterisk 1.2.18-netsec (including) 1.2.18-netsec (including)
Open_source Asterisk 1.2.19 (including) 1.2.19 (including)
Open_source Asterisk 1.2.19-netsec (including) 1.2.19-netsec (including)
Open_source Asterisk 1.2.20 (including) 1.2.20 (including)
Open_source Asterisk 1.2.20-netsec (including) 1.2.20-netsec (including)
Open_source Asterisk 1.2.21 (including) 1.2.21 (including)
Open_source Asterisk 1.2.21-netsec (including) 1.2.21-netsec (including)
Open_source Asterisk 1.2.21.1 (including) 1.2.21.1 (including)
Open_source Asterisk 1.2.21.1-netsec (including) 1.2.21.1-netsec (including)
Open_source Asterisk 1.2.22 (including) 1.2.22 (including)
Open_source Asterisk 1.2.22-netsec (including) 1.2.22-netsec (including)
Open_source Asterisk 1.2.23 (including) 1.2.23 (including)
Open_source Asterisk 1.2.23-netsec (including) 1.2.23-netsec (including)
Open_source Asterisk 1.2.24 (including) 1.2.24 (including)
Open_source Asterisk 1.2.24-netsec (including) 1.2.24-netsec (including)
Open_source Asterisk 1.2.25 (including) 1.2.25 (including)
Open_source Asterisk 1.2.25-netsec (including) 1.2.25-netsec (including)
Open_source Asterisk 1.2.26 (including) 1.2.26 (including)
Open_source Asterisk 1.2.26-netsec (including) 1.2.26-netsec (including)
Open_source Asterisk 1.2.26.1 (including) 1.2.26.1 (including)
Open_source Asterisk 1.2.26.1-netsec (including) 1.2.26.1-netsec (including)
Open_source Asterisk 1.2.26.2 (including) 1.2.26.2 (including)
Open_source Asterisk 1.2.26.2-netsec (including) 1.2.26.2-netsec (including)
Open_source Asterisk 1.4.0 (including) 1.4.0 (including)
Open_source Asterisk 1.4.0-beta2 (including) 1.4.0-beta2 (including)
Open_source Asterisk 1.4.0-beta3 (including) 1.4.0-beta3 (including)
Open_source Asterisk 1.4.0-beta4 (including) 1.4.0-beta4 (including)
Open_source Asterisk 1.4.1 (including) 1.4.1 (including)
Open_source Asterisk 1.4.10 (including) 1.4.10 (including)
Open_source Asterisk 1.4.10.1 (including) 1.4.10.1 (including)
Open_source Asterisk 1.4.11 (including) 1.4.11 (including)
Open_source Asterisk 1.4.12 (including) 1.4.12 (including)
Open_source Asterisk 1.4.12.1 (including) 1.4.12.1 (including)
Open_source Asterisk 1.4.13 (including) 1.4.13 (including)
Open_source Asterisk 1.4.14 (including) 1.4.14 (including)
Open_source Asterisk 1.4.15 (including) 1.4.15 (including)
Open_source Asterisk 1.4.16 (including) 1.4.16 (including)
Open_source Asterisk 1.4.16.1 (including) 1.4.16.1 (including)
Open_source Asterisk 1.4.16.2 (including) 1.4.16.2 (including)
Open_source Asterisk 1.4.17 (including) 1.4.17 (including)
Open_source Asterisk 1.4.18 (including) 1.4.18 (including)
Open_source Asterisk 1.4.18.1 (including) 1.4.18.1 (including)
S800i Asterisk * 1.1.0.2 (including)
S800i Asterisk 1.0 (including) 1.0 (including)
S800i Asterisk 1.0.1 (including) 1.0.1 (including)
S800i Asterisk 1.0.2 (including) 1.0.2 (including)
S800i Asterisk 1.0.3 (including) 1.0.3 (including)
S800i Asterisk 1.0.3.3 (including) 1.0.3.3 (including)
S800i Asterisk 1.1.0 (including) 1.1.0 (including)
S800i Asterisk 1.1.0.1 (including) 1.1.0.1 (including)
Asterisk Ubuntu dapper *
Asterisk Ubuntu feisty *
Asterisk Ubuntu gutsy *
Asterisk Ubuntu hardy *
Asterisk Ubuntu upstream *

Potential Mitigations

References