CVE-2012-1184
Asterisk - 'ast_parse_digest()' Stack Buffer Overflow (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.
Vulnerabilidad de desboramiento de buffer basado en memoria dinámica en la función ast_parse_digest en main/utils.c en Asterisk v1.8.x antes de v1.8.10.1 y v10.x antes de v10.2.1, permite a atacantes remotos provocar una denegación de servicio (caída) o posiblemente ejecutar código de su elección a través de una cadena larga en una cabecera HTTP Digest Authentication
Multiple vulnerabilities have been found in Asterisk, the worst of which may allow execution of arbitrary code. Versions less than 1.8.10.1 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-02-14 CVE Reserved
- 2012-03-29 CVE Published
- 2012-05-10 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://downloads.asterisk.org/pub/security/AST-2012-003-1.8.diff | X_refsource_confirm | |
http://osvdb.org/80126 | Vdb Entry | |
http://www.openwall.com/lists/oss-security/2012/03/16/10 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2012/03/16/17 | Mailing List |
|
http://www.securitytracker.com/id?1026813 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74083 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/18855 | 2012-05-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://downloads.asterisk.org/pub/security/AST-2012-003.pdf | 2017-08-29 | |
http://secunia.com/advisories/48417 | 2017-08-29 | |
http://www.asterisk.org/node/51797 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | beta1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | beta2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | beta3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | beta4 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | beta5 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | rc4 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.0" | rc5 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.1.1 Search vendor "Digium" for product "Asterisk" and version "1.8.1.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.1.2 Search vendor "Digium" for product "Asterisk" and version "1.8.1.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.2 Search vendor "Digium" for product "Asterisk" and version "1.8.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.2.1 Search vendor "Digium" for product "Asterisk" and version "1.8.2.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.2.2 Search vendor "Digium" for product "Asterisk" and version "1.8.2.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.2.3 Search vendor "Digium" for product "Asterisk" and version "1.8.2.3" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.2.4 Search vendor "Digium" for product "Asterisk" and version "1.8.2.4" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3 Search vendor "Digium" for product "Asterisk" and version "1.8.3" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3 Search vendor "Digium" for product "Asterisk" and version "1.8.3" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3 Search vendor "Digium" for product "Asterisk" and version "1.8.3" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3 Search vendor "Digium" for product "Asterisk" and version "1.8.3" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3.1 Search vendor "Digium" for product "Asterisk" and version "1.8.3.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3.2 Search vendor "Digium" for product "Asterisk" and version "1.8.3.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.3.3 Search vendor "Digium" for product "Asterisk" and version "1.8.3.3" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4 Search vendor "Digium" for product "Asterisk" and version "1.8.4" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4 Search vendor "Digium" for product "Asterisk" and version "1.8.4" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4 Search vendor "Digium" for product "Asterisk" and version "1.8.4" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4 Search vendor "Digium" for product "Asterisk" and version "1.8.4" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4.1 Search vendor "Digium" for product "Asterisk" and version "1.8.4.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4.2 Search vendor "Digium" for product "Asterisk" and version "1.8.4.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4.3 Search vendor "Digium" for product "Asterisk" and version "1.8.4.3" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.4.4 Search vendor "Digium" for product "Asterisk" and version "1.8.4.4" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.5 Search vendor "Digium" for product "Asterisk" and version "1.8.5" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.5 Search vendor "Digium" for product "Asterisk" and version "1.8.5" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.5.0 Search vendor "Digium" for product "Asterisk" and version "1.8.5.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.6.0 Search vendor "Digium" for product "Asterisk" and version "1.8.6.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.6.0 Search vendor "Digium" for product "Asterisk" and version "1.8.6.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.6.0 Search vendor "Digium" for product "Asterisk" and version "1.8.6.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.6.0 Search vendor "Digium" for product "Asterisk" and version "1.8.6.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.7.0 Search vendor "Digium" for product "Asterisk" and version "1.8.7.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.7.0 Search vendor "Digium" for product "Asterisk" and version "1.8.7.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.7.0 Search vendor "Digium" for product "Asterisk" and version "1.8.7.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.7.1 Search vendor "Digium" for product "Asterisk" and version "1.8.7.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.8.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.8.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.8.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.8.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.8.0" | rc4 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.0 Search vendor "Digium" for product "Asterisk" and version "1.8.8.0" | rc5 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.1 Search vendor "Digium" for product "Asterisk" and version "1.8.8.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.8.2 Search vendor "Digium" for product "Asterisk" and version "1.8.8.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.0 Search vendor "Digium" for product "Asterisk" and version "1.8.9.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.0 Search vendor "Digium" for product "Asterisk" and version "1.8.9.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.0 Search vendor "Digium" for product "Asterisk" and version "1.8.9.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.0 Search vendor "Digium" for product "Asterisk" and version "1.8.9.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.1 Search vendor "Digium" for product "Asterisk" and version "1.8.9.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.2 Search vendor "Digium" for product "Asterisk" and version "1.8.9.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.9.3 Search vendor "Digium" for product "Asterisk" and version "1.8.9.3" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.10.0 Search vendor "Digium" for product "Asterisk" and version "1.8.10.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.10.0 Search vendor "Digium" for product "Asterisk" and version "1.8.10.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.10.0 Search vendor "Digium" for product "Asterisk" and version "1.8.10.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.10.0 Search vendor "Digium" for product "Asterisk" and version "1.8.10.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 1.8.10.0 Search vendor "Digium" for product "Asterisk" and version "1.8.10.0" | rc4 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.0 Search vendor "Digium" for product "Asterisk" and version "10.0.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.0 Search vendor "Digium" for product "Asterisk" and version "10.0.0" | beta1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.0 Search vendor "Digium" for product "Asterisk" and version "10.0.0" | beta2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.0 Search vendor "Digium" for product "Asterisk" and version "10.0.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.0 Search vendor "Digium" for product "Asterisk" and version "10.0.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.0 Search vendor "Digium" for product "Asterisk" and version "10.0.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.0.1 Search vendor "Digium" for product "Asterisk" and version "10.0.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.1.0 Search vendor "Digium" for product "Asterisk" and version "10.1.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.1.0 Search vendor "Digium" for product "Asterisk" and version "10.1.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.1.0 Search vendor "Digium" for product "Asterisk" and version "10.1.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.1.1 Search vendor "Digium" for product "Asterisk" and version "10.1.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.1.2 Search vendor "Digium" for product "Asterisk" and version "10.1.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.1.3 Search vendor "Digium" for product "Asterisk" and version "10.1.3" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.2.0 Search vendor "Digium" for product "Asterisk" and version "10.2.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.2.0 Search vendor "Digium" for product "Asterisk" and version "10.2.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.2.0 Search vendor "Digium" for product "Asterisk" and version "10.2.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.2.0 Search vendor "Digium" for product "Asterisk" and version "10.2.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 10.2.0 Search vendor "Digium" for product "Asterisk" and version "10.2.0" | rc4 |
Affected
|