CVE-2011-0495

N/A Unknown
Published: January 20, 2011 Modified: April 29, 2026
View on NVD

Description

Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/70518
Source: cve@mitre.org
Broken Link
http://secunia.com/advisories/42935
Source: cve@mitre.org
Third Party Advisory
http://secunia.com/advisories/43119
Source: cve@mitre.org
Third Party Advisory
http://secunia.com/advisories/43373
Source: cve@mitre.org
Third Party Advisory
http://www.debian.org/security/2011/dsa-2171
Source: cve@mitre.org
Third Party Advisory
http://www.securityfocus.com/archive/1/515781/100/0/threaded
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/45839
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2011/0159
Source: cve@mitre.org
Permissions Required
http://www.vupen.com/english/advisories/2011/0281
Source: cve@mitre.org
Permissions Required
http://www.vupen.com/english/advisories/2011/0449
Source: cve@mitre.org
Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/64831
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://downloads.asterisk.org/pub/security/AST-2011-001-1.6.2.diff
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://downloads.asterisk.org/pub/security/AST-2011-001.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053689.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053713.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://osvdb.org/70518
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/42935
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/43119
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/43373
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.debian.org/security/2011/dsa-2171
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.securityfocus.com/archive/1/515781/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/45839
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2011/0159
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://www.vupen.com/english/advisories/2011/0281
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://www.vupen.com/english/advisories/2011/0449
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/64831
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry

30 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
4.2%
90th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

debian digium fedoraproject