Lucene search

K
cve[email protected]CVE-2016-9938
HistoryDec 12, 2016 - 9:59 p.m.

CVE-2016-9938

2016-12-1221:59:01
CWE-285
web.nvd.nist.gov
43
4
cve-2016-9938
asterisk
open source
authentication bypass
sip
proxy
vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

5.3 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.3%

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has a liberal definition for whitespace when attempting to strip the content between a SIP header name and a colon character. Rather than following RFC 3261 and stripping only spaces and horizontal tabs, Asterisk treats any non-printable ASCII character as if it were whitespace. This means that headers such as Contact\x01: will be seen as a valid Contact header. This mostly does not pose a problem until Asterisk is placed in tandem with an authenticating SIP proxy. In such a case, a crafty combination of valid and invalid To headers can cause a proxy to allow an INVITE request into Asterisk without authentication since it believes the request is an in-dialog request. However, because of the bug described above, the request will look like an out-of-dialog request to Asterisk. Asterisk will then process the request as a new call. The result is that Asterisk can process calls from unvetted sources without any authentication. If you do not use a proxy for authentication, then this issue does not affect you. If your proxy is dialog-aware (meaning that the proxy keeps track of what dialogs are currently valid), then this issue does not affect you. If you use chan_pjsip instead of chan_sip, then this issue does not affect you.

Affected configurations

NVD
Node
digiumasteriskMatch11.0.0
OR
digiumasteriskMatch11.0.0beta1
OR
digiumasteriskMatch11.0.0beta2
OR
digiumasteriskMatch11.0.0rc1
OR
digiumasteriskMatch11.0.0rc2
OR
digiumasteriskMatch11.0.1
OR
digiumasteriskMatch11.0.2
OR
digiumasteriskMatch11.1.0
OR
digiumasteriskMatch11.1.0rc1
OR
digiumasteriskMatch11.1.0rc3
OR
digiumasteriskMatch11.1.1
OR
digiumasteriskMatch11.1.2
OR
digiumasteriskMatch11.2.0
OR
digiumasteriskMatch11.2.0rc1
OR
digiumasteriskMatch11.2.0rc2
OR
digiumasteriskMatch11.2.1
OR
digiumasteriskMatch11.2.2
OR
digiumasteriskMatch11.3.0
OR
digiumasteriskMatch11.4.0
OR
digiumasteriskMatch11.5.0
OR
digiumasteriskMatch11.5.1
OR
digiumasteriskMatch11.6.0
OR
digiumasteriskMatch11.6.1
OR
digiumasteriskMatch11.7.0
OR
digiumasteriskMatch11.8.0
OR
digiumasteriskMatch11.8.1
OR
digiumasteriskMatch11.9.0
OR
digiumasteriskMatch11.10.0
OR
digiumasteriskMatch11.10.1
OR
digiumasteriskMatch11.10.2
OR
digiumasteriskMatch11.11.0
OR
digiumasteriskMatch11.12.0
OR
digiumasteriskMatch11.12.1
OR
digiumasteriskMatch11.13.0
OR
digiumasteriskMatch11.13.1
OR
digiumasteriskMatch11.14.0
OR
digiumasteriskMatch11.14.1
OR
digiumasteriskMatch11.14.2
OR
digiumasteriskMatch11.15.0
OR
digiumasteriskMatch11.15.1
OR
digiumasteriskMatch11.16.0
OR
digiumasteriskMatch11.17.0
OR
digiumasteriskMatch11.17.1
OR
digiumasteriskMatch11.18.0
OR
digiumasteriskMatch11.19.0
OR
digiumasteriskMatch11.20.0
OR
digiumasteriskMatch11.21.0
OR
digiumasteriskMatch11.21.1
OR
digiumasteriskMatch11.21.2
OR
digiumasteriskMatch11.22.0
OR
digiumasteriskMatch11.22.0rc1
OR
digiumasteriskMatch11.23.0
OR
digiumasteriskMatch11.23.0rc1
OR
digiumasteriskMatch11.23.1
OR
digiumasteriskMatch11.24.0
OR
digiumasteriskMatch11.24.1
OR
digiumasteriskMatch11.25.0
OR
digiumasteriskMatch13.0.0
OR
digiumasteriskMatch13.0.0beta1
OR
digiumasteriskMatch13.0.0beta2
OR
digiumasteriskMatch13.0.0beta3
OR
digiumasteriskMatch13.0.1
OR
digiumasteriskMatch13.0.2
OR
digiumasteriskMatch13.1.0
OR
digiumasteriskMatch13.1.1
OR
digiumasteriskMatch13.2.0
OR
digiumasteriskMatch13.2.1
OR
digiumasteriskMatch13.3.0
OR
digiumasteriskMatch13.3.1
OR
digiumasteriskMatch13.3.2
OR
digiumasteriskMatch13.4.0
OR
digiumasteriskMatch13.5.0
OR
digiumasteriskMatch13.6.0
OR
digiumasteriskMatch13.7.0
OR
digiumasteriskMatch13.7.1
OR
digiumasteriskMatch13.7.2
OR
digiumasteriskMatch13.8.0
OR
digiumasteriskMatch13.8.0rc1
OR
digiumasteriskMatch13.8.1
OR
digiumasteriskMatch13.8.2
OR
digiumasteriskMatch13.9.0
OR
digiumasteriskMatch13.9.1
OR
digiumasteriskMatch13.10.0
OR
digiumasteriskMatch13.10.0rc1
OR
digiumasteriskMatch13.11.0
OR
digiumasteriskMatch13.11.1
OR
digiumasteriskMatch13.11.2
OR
digiumasteriskMatch13.12.0
OR
digiumasteriskMatch13.12.1
OR
digiumasteriskMatch13.12.2
OR
digiumasteriskMatch13.13.0
OR
digiumasteriskMatch14.0.0
OR
digiumasteriskMatch14.0.0beta1
OR
digiumasteriskMatch14.0.0beta2
OR
digiumasteriskMatch14.0.0rc1
OR
digiumasteriskMatch14.0.0rc2
OR
digiumasteriskMatch14.0.1
OR
digiumasteriskMatch14.0.2
OR
digiumasteriskMatch14.1.0
OR
digiumasteriskMatch14.1.1
OR
digiumasteriskMatch14.1.2
OR
digiumasteriskMatch14.2.0
Node
digiumcertified_asteriskMatch11.0.0
OR
digiumcertified_asteriskMatch11.0.0rc1
OR
digiumcertified_asteriskMatch11.0.0rc2
OR
digiumcertified_asteriskMatch11.1.0
OR
digiumcertified_asteriskMatch11.1.0rc1
OR
digiumcertified_asteriskMatch11.1.0rc2
OR
digiumcertified_asteriskMatch11.1.0rc3
OR
digiumcertified_asteriskMatch11.2.0
OR
digiumcertified_asteriskMatch11.2.0rc1
OR
digiumcertified_asteriskMatch11.2.0rc2
OR
digiumcertified_asteriskMatch11.3.0
OR
digiumcertified_asteriskMatch11.3.0rc1
OR
digiumcertified_asteriskMatch11.3.0rc2
OR
digiumcertified_asteriskMatch11.4.0
OR
digiumcertified_asteriskMatch11.4.0rc1
OR
digiumcertified_asteriskMatch11.4.0rc2
OR
digiumcertified_asteriskMatch11.4.0rc3
OR
digiumcertified_asteriskMatch11.5.0
OR
digiumcertified_asteriskMatch11.5.0rc1
OR
digiumcertified_asteriskMatch11.5.0rc2
OR
digiumcertified_asteriskMatch11.6cert1
OR
digiumcertified_asteriskMatch11.6cert1lts
OR
digiumcertified_asteriskMatch11.6cert1_rc1
OR
digiumcertified_asteriskMatch11.6cert1_rc2
OR
digiumcertified_asteriskMatch11.6cert10lts
OR
digiumcertified_asteriskMatch11.6cert11lts
OR
digiumcertified_asteriskMatch11.6cert12lts
OR
digiumcertified_asteriskMatch11.6cert13lts
OR
digiumcertified_asteriskMatch11.6cert14lts
OR
digiumcertified_asteriskMatch11.6cert15lts
OR
digiumcertified_asteriskMatch11.6cert2
OR
digiumcertified_asteriskMatch11.6cert2lts
OR
digiumcertified_asteriskMatch11.6cert3
OR
digiumcertified_asteriskMatch11.6cert3lts
OR
digiumcertified_asteriskMatch11.6cert4lts
OR
digiumcertified_asteriskMatch11.6cert5lts
OR
digiumcertified_asteriskMatch11.6cert6lts
OR
digiumcertified_asteriskMatch11.6cert7lts
OR
digiumcertified_asteriskMatch11.6cert8lts
OR
digiumcertified_asteriskMatch11.6cert9lts
OR
digiumcertified_asteriskMatch11.6.0lts
OR
digiumcertified_asteriskMatch11.6.0-
OR
digiumcertified_asteriskMatch11.6.0rc1
OR
digiumcertified_asteriskMatch11.6.0rc2

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

5.3 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.3%