Asterisk contains a NULL pointer dereference flaw in the 'handle_request_info()' function [channels/chan_sip.c] that may allow a remote denial of service when the 'automon' feature is enabled (disabled by default). With a specially crafted sequence of SIP packets, a remote attacker can cause the service to crash.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Voice over IP
Solution
Upgrade to version 1.6.2.21 or higher or 1.8.7.2 or higher, as it has been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.