>> Asterisk SIP Channel Driver Request Handling Remote Denial of Service Vulnerability
Title : Asterisk SIP Channel Driver Request Handling Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4098 CVE ID : CVE-2006-5445
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-19
Technical Description
A vulnerability has been identified in Asterisk, which could be exploited by remote attackers to cause a denial of service. This flaw is due to an error in the SIP channel driver [chan_sip.c] that erroneously creates a "pvt" structure for certain requests that should not normally be able to create one, which could be exploited by remote attackers to exhaust all available resources, creating a denial of service condition.