Vulnerability Name: CVE-2009-2726 (CCN-52391) Assigned: 2009-08-10 Published: 2009-08-10 Updated: 2018-10-10 Summary: The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-399 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2009-2726 Source: CCN Type: AST-2009-005Remote Crash Vulnerability in SIP channel driver Source: CONFIRM Type: UNKNOWNhttp://downloads.digium.com/pub/security/AST-2009-005.html Source: CCN Type: [MU-200908-01] August 10, 2009Multiple sscanf vulnerabilities in Asterisk Source: MISC Type: UNKNOWNhttp://labs.mudynamics.com/advisories/MU-200908-01.txt Source: CCN Type: SA36227Asterisk SIP Channel Driver Denial of Service Source: SECUNIA Type: Vendor Advisory36227 Source: CCN Type: SECTRACK ID: 1022705Asterisk Bug in Processing SIP Packets Lets Remote Users Deny Service Source: CCN Type: GLSA-201006-20Asterisk: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 56991Asterisk Multiple Function Maximum Width Handling Remote DoS Source: BUGTRAQ Type: UNKNOWN20090811 AST-2009-005: Remote Crash Vulnerability in SIP channel driver Source: BID Type: Exploit36015 Source: CCN Type: BID-36015Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service Vulnerabilities Source: SECTRACK Type: UNKNOWN1022705 Source: VUPEN Type: Vendor AdvisoryADV-2009-2229 Source: XF Type: UNKNOWNasterisk-sscanf-dos(52391) Vulnerable Configuration: Configuration 1 :cpe:/a:asterisk:business_edition:b.1.3.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:business_edition:c.2.3:*:*:*:*:*:*:* OR cpe:/a:asterisk:business_edition:c.3.0:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.0:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.0:beta1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.0:beta2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.0:rc1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.0:rc2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.2:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.3:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.3:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.4:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.4:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.5:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.5:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.6:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.6:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.7:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.7:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.7.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.7.1:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.8:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.8:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.9.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.9.1:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.10:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.10:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.11:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.11:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.12:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.12:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.12.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.12.1:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.13:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.13:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.14:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.15:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.15:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.16:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.16:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.17:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.17:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.18:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.18:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.19:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.19:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.20:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.20:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.21:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.21:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.21.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.21.1:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.22:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.22:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.23:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.23:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.24:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.24:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.25:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.25:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.26:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.26:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.26.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.26.1:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.26.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.26.2:netsec:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.27:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.28:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.29:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.30:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.30.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.30.3:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.2.30.4:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.0:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.0:beta2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.0:beta3:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.0:beta4:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.3:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.4:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.5:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.6:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.7:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.7.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.8:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.9:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.10:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.10.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.11:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.12:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.12.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.13:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.14:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.15:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.16:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.16.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.16.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.17:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.18:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.18.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19:rc-2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19:rc1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19:rc2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19:rc3:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19:rc4:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.19_rc3:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.20:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.20:rc1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.20:rc2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.20:rc3:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.21:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.21:rc1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.21:rc2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.21.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.21.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.22:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.22:rc3:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.22:rc4:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.22.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.22.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.23:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.23:rc1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.23:rc2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4.23:rc3:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.4beta:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta2:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta3:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta4:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta5:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta7:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta7.1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta8:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:beta9:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:rc4:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:rc5:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0:rc6:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0.2:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0.3:*:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.0.3:rc1:*:*:*:*:*:* OR cpe:/a:asterisk:open_source:1.6.1:*:*:*:*:*:*:* OR cpe:/a:asterisk:opensource:1.4.22:*:*:*:*:*:*:* OR cpe:/a:asterisk:opensource:1.4.23:*:*:*:*:*:*:* OR cpe:/a:asterisk:opensource:1.4.23.1:*:*:*:*:*:*:* OR cpe:/h:asterisk:appliance_s800i:1.3.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
asterisk business edition b.1.3.2
asterisk business edition c.2.3
asterisk business edition c.3.0
asterisk open source 1.2.0
asterisk open source 1.2.0 beta1
asterisk open source 1.2.0 beta2
asterisk open source 1.2.0 rc1
asterisk open source 1.2.0 rc2
asterisk open source 1.2.1
asterisk open source 1.2.2
asterisk open source 1.2.2 netsec
asterisk open source 1.2.3
asterisk open source 1.2.3 netsec
asterisk open source 1.2.4
asterisk open source 1.2.4 netsec
asterisk open source 1.2.5
asterisk open source 1.2.5 netsec
asterisk open source 1.2.6
asterisk open source 1.2.6 netsec
asterisk open source 1.2.7
asterisk open source 1.2.7 netsec
asterisk open source 1.2.7.1
asterisk open source 1.2.7.1 netsec
asterisk open source 1.2.8
asterisk open source 1.2.8 netsec
asterisk open source 1.2.9.1
asterisk open source 1.2.9.1 netsec
asterisk open source 1.2.10
asterisk open source 1.2.10 netsec
asterisk open source 1.2.11
asterisk open source 1.2.11 netsec
asterisk open source 1.2.12
asterisk open source 1.2.12 netsec
asterisk open source 1.2.12.1
asterisk open source 1.2.12.1 netsec
asterisk open source 1.2.13
asterisk open source 1.2.13 netsec
asterisk open source 1.2.14 netsec
asterisk open source 1.2.15
asterisk open source 1.2.15 netsec
asterisk open source 1.2.16
asterisk open source 1.2.16 netsec
asterisk open source 1.2.17
asterisk open source 1.2.17 netsec
asterisk open source 1.2.18
asterisk open source 1.2.18 netsec
asterisk open source 1.2.19
asterisk open source 1.2.19 netsec
asterisk open source 1.2.20
asterisk open source 1.2.20 netsec
asterisk open source 1.2.21
asterisk open source 1.2.21 netsec
asterisk open source 1.2.21.1
asterisk open source 1.2.21.1 netsec
asterisk open source 1.2.22
asterisk open source 1.2.22 netsec
asterisk open source 1.2.23
asterisk open source 1.2.23 netsec
asterisk open source 1.2.24
asterisk open source 1.2.24 netsec
asterisk open source 1.2.25
asterisk open source 1.2.25 netsec
asterisk open source 1.2.26
asterisk open source 1.2.26 netsec
asterisk open source 1.2.26.1
asterisk open source 1.2.26.1 netsec
asterisk open source 1.2.26.2
asterisk open source 1.2.26.2 netsec
asterisk open source 1.2.27
asterisk open source 1.2.28
asterisk open source 1.2.29
asterisk open source 1.2.30
asterisk open source 1.2.30.2
asterisk open source 1.2.30.3
asterisk open source 1.2.30.4
asterisk open source 1.4.0
asterisk open source 1.4.0 beta2
asterisk open source 1.4.0 beta3
asterisk open source 1.4.0 beta4
asterisk open source 1.4.1
asterisk open source 1.4.2
asterisk open source 1.4.3
asterisk open source 1.4.4
asterisk open source 1.4.5
asterisk open source 1.4.6
asterisk open source 1.4.7
asterisk open source 1.4.7.1
asterisk open source 1.4.8
asterisk open source 1.4.9
asterisk open source 1.4.10
asterisk open source 1.4.10.1
asterisk open source 1.4.11
asterisk open source 1.4.12
asterisk open source 1.4.12.1
asterisk open source 1.4.13
asterisk open source 1.4.14
asterisk open source 1.4.15
asterisk open source 1.4.16
asterisk open source 1.4.16.1
asterisk open source 1.4.16.2
asterisk open source 1.4.17
asterisk open source 1.4.18
asterisk open source 1.4.18.1
asterisk open source 1.4.19
asterisk open source 1.4.19 rc-2
asterisk open source 1.4.19 rc1
asterisk open source 1.4.19 rc2
asterisk open source 1.4.19 rc3
asterisk open source 1.4.19 rc4
asterisk open source 1.4.19.1
asterisk open source 1.4.19.2
asterisk open source 1.4.19_rc3
asterisk open source 1.4.20
asterisk open source 1.4.20 rc1
asterisk open source 1.4.20 rc2
asterisk open source 1.4.20 rc3
asterisk open source 1.4.21
asterisk open source 1.4.21 rc1
asterisk open source 1.4.21 rc2
asterisk open source 1.4.21.1
asterisk open source 1.4.21.2
asterisk open source 1.4.22
asterisk open source 1.4.22 rc3
asterisk open source 1.4.22 rc4
asterisk open source 1.4.22.1
asterisk open source 1.4.22.2
asterisk open source 1.4.23
asterisk open source 1.4.23 rc1
asterisk open source 1.4.23 rc2
asterisk open source 1.4.23 rc3
asterisk open source 1.4beta
asterisk open source 1.6.0 beta1
asterisk open source 1.6.0 beta2
asterisk open source 1.6.0 beta3
asterisk open source 1.6.0 beta4
asterisk open source 1.6.0 beta5
asterisk open source 1.6.0 beta7
asterisk open source 1.6.0 beta7.1
asterisk open source 1.6.0 beta8
asterisk open source 1.6.0 beta9
asterisk open source 1.6.0 rc4
asterisk open source 1.6.0 rc5
asterisk open source 1.6.0 rc6
asterisk open source 1.6.0.1
asterisk open source 1.6.0.2
asterisk open source 1.6.0.3
asterisk open source 1.6.0.3 rc1
asterisk open source 1.6.1
asterisk opensource 1.4.22
asterisk opensource 1.4.23
asterisk opensource 1.4.23.1
asterisk appliance s800i 1.3.0.2