Description: MU Security Research Team has reported a vulnerability in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a NULL-pointer dereference error when handling SIP request messages. This can be exploited to crash the service via a specially crafted SIP message with no URI and SIP version sent to default port 5060/UDP.
The vulnerability is reported in version 1.4.0 and 1.2.15. Prior versions may also be affected.
Solution: Update to version 1.4.1 or 1.2.16.
Provided and/or discovered by: MU Security Research Team
Changelog: 2007-03-08: Updated description to include additional information from MU Security.
2007-03-19: Added CVE reference.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.