Unrated severityNVD Advisory· Published Jan 20, 2011· Updated Apr 29, 2026
CVE-2011-0495
CVE-2011-0495
Description
Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.
Affected products
7- cpe:2.3:a:digium:asterisknow:1.5:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:digium:s800i_firmware:1.2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- downloads.asterisk.org/pub/security/AST-2011-001-1.6.2.diffnvdPatchVendor Advisory
- downloads.asterisk.org/pub/security/AST-2011-001.htmlnvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2011-February/053689.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2011-February/053713.htmlnvdThird Party Advisory
- secunia.com/advisories/42935nvdThird Party Advisory
- secunia.com/advisories/43119nvdThird Party Advisory
- secunia.com/advisories/43373nvdThird Party Advisory
- www.debian.org/security/2011/dsa-2171nvdThird Party Advisory
- www.securityfocus.com/archive/1/515781/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/45839nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/64831nvdThird Party AdvisoryVDB Entry
- osvdb.org/70518nvdBroken Link
- www.vupen.com/english/advisories/2011/0159nvdPermissions Required
- www.vupen.com/english/advisories/2011/0281nvdPermissions Required
- www.vupen.com/english/advisories/2011/0449nvdPermissions Required
News mentions
0No linked articles in our index yet.