There is a command injection vulnerability in AsteriDex default config, which allows unauthenticated users to execute arbitrary commands on the Asterisk console. Such access permits execution of arbitrary operating system commands as the 'asterisk' user.
A vulnerability in the SIP channel driver (channels/chan_sip.c) in all versions of Asterisk prior to 1.2.13. Local and remote attackers are able to cause a denial of service (resource consumption) via unspecified vectors that result in the creation of "a