Asterisk Project Security Advisory – AST-2011-011

0
42

Asterisk Project Security Advisory – Asterisk may respond differently to SIP requests from an invalid SIP user than it does to a user configured on the system, even when the alwaysauthreject option is set in the configuration. This can leak information about what SIP users are valid on the Asterisk system.

Source: Asterisk Project Security Advisory – AST-2011-011