{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "state": "PUBLISHED", "cveId": "CVE-2008-1897", "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "dateUpdated": "2024-08-07T08:40:59.845Z", "dateReserved": "2008-04-20T00:00:00.000Z", "datePublished": "2008-04-23T00:00:00.000Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre", "dateUpdated": "2023-10-20T02:02:11.362Z" }, "descriptions": [ { "lang": "en", "value": "The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923." } ], "affected": [ { "vendor": "n/a", "product": "n/a", "versions": [ { "version": "n/a", "status": "affected" } ] } ], "references": [ { "name": "GLSA-200905-01", "tags": [ "vendor-advisory" ], "url": "http://security.gentoo.org/glsa/glsa-200905-01.xml" }, { "name": "29927", "tags": [ "third-party-advisory" ], "url": "http://secunia.com/advisories/29927" }, { "name": "asterisk-iax2protocol-ack-dos(41966)", "tags": [ "vdb-entry" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41966" }, { "name": "28901", "tags": [ "vdb-entry" ], "url": "http://www.securityfocus.com/bid/28901" }, { "name": "30010", "tags": [ "third-party-advisory" ], "url": "http://secunia.com/advisories/30010" }, { "name": "ADV-2008-1324", "tags": [ "vdb-entry" ], "url": "http://www.vupen.com/english/advisories/2008/1324" }, { "url": "http://downloads.digium.com/pub/security/AST-2008-006.html" }, { "url": "http://bugs.digium.com/view.php?id=10078" }, { "name": "FEDORA-2008-3390", "tags": [ "vendor-advisory" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00600.html" }, { "name": "20080422 AST-2008-006 - 3-way handshake in IAX2 incomplete", "tags": [ "mailing-list" ], "url": "http://www.securityfocus.com/archive/1/491220/100/0/threaded" }, { "url": "http://www.altsci.com/concepts/page.php?s=asteri&p=2" }, { "name": "30042", "tags": [ "third-party-advisory" ], "url": "http://secunia.com/advisories/30042" }, { "name": "DSA-1563", "tags": [ "vendor-advisory" ], "url": "http://www.debian.org/security/2008/dsa-1563" }, { "name": "34982", "tags": [ "third-party-advisory" ], "url": "http://secunia.com/advisories/34982" }, { "name": "1019918", "tags": [ "vdb-entry" ], "url": "http://www.securitytracker.com/id?1019918" }, { "name": "FEDORA-2008-3365", "tags": [ "vendor-advisory" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00581.html" }, { "url": "https://downloads.asterisk.org/pub/security/AST-2008-006.html" }, { "url": "https://github.com/xrg/asterisk-xrg/commit/51714a24347dc57f9a208a4a8af84115ef407b83" }, { "url": "https://github.com/jcollie/asterisk/commit/a8b180875b037b8da26f6a3bcc8e5e98b8c904d2" }, { "url": "https://github.com/xrg/asterisk-xrg/commit/10da3dab24e8ca08cf2c983f8d0206e383535b5a" }, { "url": "https://github.com/jcollie/asterisk/commit/771b3d8749b34b6eea4e03a2e514380da9582f90" }, { "url": "https://github.com/pruiz/asterisk/commit/e0ef9bd22810c6969a7f222eec04798f19a7e2d6" }, { "url": "https://github.com/jcollie/asterisk/commit/60de4fbbdf3ede49f158e23a9e3b679f2e519c1e" }, { "url": "https://github.com/mojolingo/asterisk/commit/20ac3662f137dbf7f42d5295590069a7d3b1166b" }, { "url": "https://github.com/silentindark/asterisk-1/commit/fe8b7f31db687f8b9992864b82c93d22833019c7" }, { "url": "https://github.com/kaoru6/asterisk/commit/1fe14f38dd43dc894d21f85762b51208ba5c8acb" }, { "url": "https://github.com/lyx2014/Asterisk/commit/0670e43c30135044e25cca7f80e1833e2c128653" } ], "problemTypes": [ { "descriptions": [ { "type": "text", "lang": "en", "description": "n/a" } ] } ], "datePublic": "2008-04-22T00:00:00.000Z" }, "adp": [ { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-07T08:40:59.845Z" }, "title": "CVE Program Container", "references": [ { "name": "GLSA-200905-01", "tags": [ "vendor-advisory", "x_transferred" ], "url": "http://security.gentoo.org/glsa/glsa-200905-01.xml" }, { "name": "29927", "tags": [ "third-party-advisory", "x_transferred" ], "url": "http://secunia.com/advisories/29927" }, { "name": "asterisk-iax2protocol-ack-dos(41966)", "tags": [ "vdb-entry", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41966" }, { "name": "28901", "tags": [ "vdb-entry", "x_transferred" ], "url": "http://www.securityfocus.com/bid/28901" }, { "name": "30010", "tags": [ "third-party-advisory", "x_transferred" ], "url": "http://secunia.com/advisories/30010" }, { "name": "ADV-2008-1324", "tags": [ "vdb-entry", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2008/1324" }, { "url": "http://downloads.digium.com/pub/security/AST-2008-006.html", "tags": [ "x_transferred" ] }, { "url": "http://bugs.digium.com/view.php?id=10078", "tags": [ "x_transferred" ] }, { "name": "FEDORA-2008-3390", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00600.html" }, { "name": "20080422 AST-2008-006 - 3-way handshake in IAX2 incomplete", "tags": [ "mailing-list", "x_transferred" ], "url": "http://www.securityfocus.com/archive/1/491220/100/0/threaded" }, { "url": "http://www.altsci.com/concepts/page.php?s=asteri&p=2", "tags": [ "x_transferred" ] }, { "name": "30042", "tags": [ "third-party-advisory", "x_transferred" ], "url": "http://secunia.com/advisories/30042" }, { "name": "DSA-1563", "tags": [ "vendor-advisory", "x_transferred" ], "url": "http://www.debian.org/security/2008/dsa-1563" }, { "name": "34982", "tags": [ "third-party-advisory", "x_transferred" ], "url": "http://secunia.com/advisories/34982" }, { "name": "1019918", "tags": [ "vdb-entry", "x_transferred" ], "url": "http://www.securitytracker.com/id?1019918" }, { "name": "FEDORA-2008-3365", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00581.html" }, { "url": "https://downloads.asterisk.org/pub/security/AST-2008-006.html", "tags": [ "x_transferred" ] }, { "url": "https://github.com/xrg/asterisk-xrg/commit/51714a24347dc57f9a208a4a8af84115ef407b83", "tags": [ "x_transferred" ] }, { "url": "https://github.com/jcollie/asterisk/commit/a8b180875b037b8da26f6a3bcc8e5e98b8c904d2", "tags": [ "x_transferred" ] }, { "url": "https://github.com/xrg/asterisk-xrg/commit/10da3dab24e8ca08cf2c983f8d0206e383535b5a", "tags": [ "x_transferred" ] }, { "url": "https://github.com/jcollie/asterisk/commit/771b3d8749b34b6eea4e03a2e514380da9582f90", "tags": [ "x_transferred" ] }, { "url": "https://github.com/pruiz/asterisk/commit/e0ef9bd22810c6969a7f222eec04798f19a7e2d6", "tags": [ "x_transferred" ] }, { "url": "https://github.com/jcollie/asterisk/commit/60de4fbbdf3ede49f158e23a9e3b679f2e519c1e", "tags": [ "x_transferred" ] }, { "url": "https://github.com/mojolingo/asterisk/commit/20ac3662f137dbf7f42d5295590069a7d3b1166b", "tags": [ "x_transferred" ] }, { "url": "https://github.com/silentindark/asterisk-1/commit/fe8b7f31db687f8b9992864b82c93d22833019c7", "tags": [ "x_transferred" ] }, { "url": "https://github.com/kaoru6/asterisk/commit/1fe14f38dd43dc894d21f85762b51208ba5c8acb", "tags": [ "x_transferred" ] }, { "url": "https://github.com/lyx2014/Asterisk/commit/0670e43c30135044e25cca7f80e1833e2c128653", "tags": [ "x_transferred" ] } ] } ] } }