Vulnerability Description
Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames via multiple crafted REGISTER messages with inconsistent usernames in the URI in the To header and the Digest in the Authorization header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | 1.2.0 |
| Digium | Asterisknow | 1.5 |
| Digium | S800I | 1.3.0 |
Related Weaknesses (CWE)
References
- http://downloads.asterisk.org/pub/security/AST-2009-008.htmlVendor Advisory
- http://osvdb.org/59697
- http://secunia.com/advisories/37265Vendor Advisory
- http://secunia.com/advisories/37479
- http://secunia.com/advisories/37677
- http://www.debian.org/security/2009/dsa-1952
- http://www.securityfocus.com/bid/36924Patch
- http://www.securitytracker.com/id?1023133
- https://bugzilla.redhat.com/show_bug.cgi?id=523277
- https://bugzilla.redhat.com/show_bug.cgi?id=533137
- https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00789.h
- https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00838.h
- http://downloads.asterisk.org/pub/security/AST-2009-008.htmlVendor Advisory
- http://osvdb.org/59697
- http://secunia.com/advisories/37265Vendor Advisory
FAQ
What is CVE-2009-3727?
CVE-2009-3727 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x...
How severe is CVE-2009-3727?
CVE-2009-3727 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3727?
Check the references section above for vendor advisories and patch information. Affected products include: Digium Asterisk, Digium Asterisknow, Digium S800I.