---
title: "CVE-2011-1507\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-1507?format=md
keywords: index, follow
---

# CVE-2011-1507

Publication date 27 April 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25,
1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business
Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated
sessions to certain interfaces, which allows remote attackers to cause a
denial of service (file descriptor exhaustion and disk space exhaustion)
via a series of TCP connections.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| asterisk | 11.04 natty | Fixed 1:1.6.2.9-2ubuntu2.1 |
| 10.10 maverick | Fixed 1:1.6.2.7-1ubuntu1.2 |
| 10.04 LTS lucid | Fixed 1:1.6.2.5-0ubuntu1.4 |
| 9.10 karmic | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-1507?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| asterisk | * Upstream:   <http://downloads.asterisk.org/pub/security/AST-2011-005-1.6.2.diff> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1507)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-1507)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-1507)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-1507)

### Other references

* <http://downloads.asterisk.org/pub/security/AST-2011-005.html>
* <https://www.cve.org/CVERecord?id=CVE-2011-1507>
