what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 5 of 5 RSS Feed

Files from Ben Ford

Email addressbford at sangoma.com
First Active2019-11-21
Last Active2022-04-15
Asterisk Project Security Advisory - AST-2022-002
Posted Apr 15, 2022
Authored by Ben Ford, Clint Ruoho | Site asterisk.org

Asterisk suffers from a server-side request forgery vulnerability. When using STIR/SHAKEN, it is possible to send arbitrary requests like GET to interfaces such as localhost using the Identity header. Asterisk Open Source versions 16.15.0 up to but not including 16.25.2, 18.x up to but not including 18.11.2, and 19.x up to but not including 19.3.2 are affected.

tags | advisory, arbitrary
advisories | CVE-2022-26499
SHA-256 | 7727f89aa5888d067b6bf9ed78cdb7e6304adf0a733433e0687a3678d88eb17b
Asterisk Project Security Advisory - AST-2022-001
Posted Apr 15, 2022
Authored by Ben Ford | Site asterisk.org

When using STIR/SHAKEN in Asterisk, it is possible to download files that are not certificates. These files could be much larger than what you would expect to download. Asterisk Open Source versions 16.15.0 up to but not including 16.25.2, 18.x up to but not including 18.11.2, and 19.x up to but not including 19.3.2 are affected.

tags | advisory
advisories | CVE-2022-26498
SHA-256 | 1fc78214ca3a80d4d46428ca4fdf01c6fc39ae8d4fd32be3d9c901d7bd98b5b1
Asterisk Project Security Advisory - AST-2020-002
Posted Nov 6, 2020
Authored by Ben Ford, Sebastian Damm, Ruslan Lazin | Site asterisk.org

Asterisk Project Security Advisory - If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume more and more memory since the transaction will never terminate (even if the call is hung up), ultimately leading to a restart or shutdown of Asterisk. Outbound authentication must be configured on the endpoint for this to occur.

tags | advisory
SHA-256 | 7b5bf722297267d2f92ffbd9c74ee0315153dc145925d137aff58dbd10bcf95e
Asterisk Project Security Advisory - AST-2019-008
Posted Nov 21, 2019
Authored by Ben Ford, Salah Ahmed | Site asterisk.org

Asterisk Project Security Advisory - If Asterisk receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a crash will occur.

tags | advisory
advisories | CVE-2019-18976
SHA-256 | 01b4f0b91afa8ead00f323fea3922b3d1fb27aa6ab6e1d11f3fb55cdeac8d9c1
Asterisk Project Security Advisory - AST-2019-006
Posted Nov 21, 2019
Authored by Ben Ford | Site asterisk.org

Asterisk Project Security Advisory - A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result.

tags | advisory
advisories | CVE-2019-18790
SHA-256 | f6ef15929258c9bf9a7eb09fc36ce5def67a2b9d5cf46bd3dd3f473a58858b6f
Page 1 of 1
Back1Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close