Unrated severityNVD Advisory· Published Sep 4, 2008· Updated Apr 23, 2026
CVE-2008-3903
CVE-2008-3903
Description
Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, when Digest authentication and authalwaysreject are enabled, generates different responses depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames.
Affected products
5Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- downloads.asterisk.org/pub/security/AST-2009-003.htmlnvd
- misel.comnvd
- secunia.com/advisories/34982nvd
- secunia.com/advisories/37677nvd
- security.gentoo.org/glsa/glsa-200905-01.xmlnvd
- www.debian.org/security/2009/dsa-1952nvd
- www.securityfocus.com/bid/34353nvd
- www.vupen.com/english/advisories/2009/0933nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45059nvd
News mentions
0No linked articles in our index yet.