CVE-2012-1184

high
Published 2012-09-18 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.asterisk.org/node/51797

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48417

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://downloads.asterisk.org/pub/security/AST-2012-003.pdf

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-1184

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed1:1.8.10.0~dfsg-1
debian debiansidfixed1:1.8.10.0~dfsg-1

Application impact

VendorProductVersionsFixed
digiumasterisk1.8.0
digiumasterisk1.8.1.1
digiumasterisk1.8.1.2
digiumasterisk1.8.2
digiumasterisk1.8.2.1
digiumasterisk1.8.2.2
digiumasterisk1.8.2.3
digiumasterisk1.8.2.4
digiumasterisk1.8.3
digiumasterisk1.8.3.1
digiumasterisk1.8.3.2
digiumasterisk1.8.3.3
digiumasterisk1.8.4
digiumasterisk1.8.4.1
digiumasterisk1.8.4.2
digiumasterisk1.8.4.3
digiumasterisk1.8.4.4
digiumasterisk1.8.5
digiumasterisk1.8.5.0
digiumasterisk1.8.6.0
digiumasterisk1.8.7.0
digiumasterisk1.8.7.1
digiumasterisk1.8.8.0
digiumasterisk1.8.8.1
digiumasterisk1.8.8.2
digiumasterisk1.8.9.0
digiumasterisk1.8.9.1
digiumasterisk1.8.9.2
digiumasterisk1.8.9.3
digiumasterisk1.8.10.0
digiumasterisk10.0.0
digiumasterisk10.0.1
digiumasterisk10.1.0
digiumasterisk10.1.1
digiumasterisk10.1.2
digiumasterisk10.1.3
digiumasterisk10.2.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.