Release date: 2011-12-08
Updated on: 2011-12-09
Affected Systems:
Asterisk 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50990
Asterisk is a free and open-source software that enables the Telephone User Switch (PBX) function.
Asterisk has a security vulnerability. Attackers can exploit this vulnerability to obtain valid user names.
When the regular, user/peer NAT sets different ports for responding to the request source port or the port list in the Via header, the SIP user name may be enumerated.
<* Source: Terry Wilson
Link: http://seclists.org/fulldisclosure/2011/Dec/254
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://downloads.asterisk.org/pub/security/