| Name | CVE-2009-2726 |
| Description | The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 541441 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| asterisk (PTS) | bullseye | 1:16.28.0~dfsg-0+deb11u4 | fixed |
| bullseye (security) | 1:16.28.0~dfsg-0+deb11u8 | fixed | |
| sid | 1:22.6.0~dfsg+~cs6.15.60671435-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| asterisk | source | etch | (not affected) | |||
| asterisk | source | lenny | (not affected) | |||
| asterisk | source | squeeze | (not affected) | |||
| asterisk | source | (unstable) | 1:1.6.2.0~dfsg~rc1-1 | 541441 |
[squeeze] - asterisk <not-affected> (Doesn't permit SIP packets to exceed 1500 bytes total)
[lenny] - asterisk <not-affected> (Doesn't permit SIP packets to exceed 1500 bytes total)
[etch] - asterisk <not-affected> (Doesn't permit SIP packets to exceed 1500 bytes total)