← Back

CVE-2009-0041

nvd nist
Published: Jan 14, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

Affected (150)

3 products
Asterisk Business Edition
Open Source
S800i Appliance
Configuration A
150 vulnerable
Vulnerable SoftwareAffected Versions
Asterisk
Up to b.2.5.2
Up to c.1.0
Version a
Version b.1.3.2
Version b.1.3.3
Version b.2.2.0
Version b.2.2.1
Version b.2.3.1
Version b.2.3.2
Version b.2.3.3
Version b.2.3.4
Version b.2.3.5
Version b.2.3.6
Version b.2.5.0
Version b.2.5.1
Version b.2.5.3
Version c.1.0 beta7
Asterisk
Up to 1.2.30.4
Up to 1.6.0.3
Up to 1.4.23
Version 1.2.0
Version 1.2.0 beta1
Version 1.2.0 beta2
Version 1.2.0 rc1
Version 1.2.0 rc2
Version 1.2.0beta1
Version 1.2.0beta2
Version 1.2.10
Version 1.2.10 netsec
Version 1.2.11
Version 1.2.11 netsec
Version 1.2.12.1
Version 1.2.12.1 netsec
Version 1.2.12
Version 1.2.12 netsec
Version 1.2.13
Version 1.2.13 netsec
Version 1.2.14
Version 1.2.14 netsec
Version 1.2.15
Version 1.2.15 netsec
Version 1.2.16
Version 1.2.16 netsec
Version 1.2.17
Version 1.2.17 netsec
Version 1.2.18
Version 1.2.18 netsec
Version 1.2.19
Version 1.2.19 netsec
Version 1.2.1
Version 1.2.20
Version 1.2.20 netsec
Version 1.2.21.1
Version 1.2.21.1 netsec
Version 1.2.21
Version 1.2.21 netsec
Version 1.2.22
Version 1.2.22 netsec
Version 1.2.23
Version 1.2.23 netsec
Version 1.2.24
Version 1.2.24 netsec
Version 1.2.25
Version 1.2.25 netsec
Version 1.2.26.1
Version 1.2.26.1 netsec
Version 1.2.26.2
Version 1.2.26.2 netsec
Version 1.2.26
Version 1.2.26 netsec
Version 1.2.27
Version 1.2.28
Version 1.2.29
Version 1.2.2
Version 1.2.2 netsec
Version 1.2.30.2
Version 1.2.30.3
Version 1.2.30
Version 1.2.3
Version 1.2.3 netsec
Version 1.4.0
Version 1.4.0 beta2
Version 1.4.0 beta3
Version 1.4.0 beta4
Version 1.4.10.1
Version 1.4.10
Version 1.4.11
Version 1.4.12.1
Version 1.4.12
Version 1.4.13
Version 1.4.14
Version 1.4.15
Version 1.4.16.1
Version 1.4.16.2
Version 1.4.16
Version 1.4.17
Version 1.4.18.1
Version 1.4.18
Version 1.4.19.1
Version 1.4.19.2
Version 1.4.19
Version 1.4.19 rc1
Version 1.4.19 rc2
Version 1.4.19 rc3
Version 1.4.19 rc4
Version 1.4.1
Version 1.4.20
Version 1.4.20 rc1
Version 1.4.20 rc2
Version 1.4.20 rc3
Version 1.4.21.1
Version 1.4.21.2
Version 1.4.21
Version 1.4.21 rc1
Version 1.4.21 rc2
Version 1.4.22.1
Version 1.4.22.2
Version 1.4.22
Version 1.4.22 rc3
Version 1.4.22 rc4
Version 1.4.23
Version 1.4.23 rc1
Version 1.4.23 rc2
Version 1.4.2
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7.1
Version 1.4.7
Version 1.4.8
Version 1.4.9
Version 1.4_revision_95946
Version 1.4beta
Version 1.6.0.1
Version 1.6.0.2
Version 1.6.0.3
Version 1.6.0 beta1
Version 1.6.0 beta2
Version 1.6.0 beta3
Version 1.6.0 beta4
Version 1.6.0 beta5
Version 1.6.0 beta7.1
Version 1.6.0 beta7
Version 1.6.0 beta8
Version 1.6.0 beta9
Version 1.6.0 rc4
Version 1.6.0 rc5
Version 1.6.0 rc6
Version 1.2

References (22)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.