Asterisk contains a flaw that may allow an attacker to determine valid usernames. The issue is triggered when different responses are being sent using a valid or an invalid username in 'REGISTER' messages. This can be exploited to determine valid usernames by sending a specially crafted 'REGISTER' message. .
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS,
Upgrade
Disclosure:
Vendor Verified
Solution
Upgrade to version 1.2.35, 1.4.26.3, 1.6.0.17, 1.6.19 or higher, as it has been reported to fix this vulnerability. In addition, Digium has released a patch for some older versions.