Vulnerable Systems:
* Asterisk Open Source version 1.6.1
Immune Systems:
* Asterisk Open Source version 1.6.1.8
A missing ACL check for handling SIP INVITEs allows a device to make calls on networks intended to be prohibited as defined by the "deny" and "permit" lines in sip.conf. The ACL check for handling SIP registrations was not affected