Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Asterisk IAX 'POKE' Requests Remote Denial of Service Vulnerability

Asterisk is prone to a remote denial-of-service vulnerability because it fails to handle multiple 'POKE' requests in quick succession.

Attackers can exploit this issue by sending a persistent stream of 'POKE' requests that will consume processor resources and deny service to legitimate users.

NOTE: By default, 'POKE' requests are not logged by Asterisk.







 

Privacy Statement
Copyright 2008, SecurityFocus