7.8
CVSSv2

CVE-2006-5445

Published: 23/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Unspecified vulnerability in the SIP channel driver (channels/chan_sip.c) in Asterisk 1.2.x prior to 1.2.13 and 1.4.x prior to 1.4.0-beta3 allows remote malicious users to cause a denial of service (resource consumption) via unspecified vectors that result in the creation of "a real pvt structure" that uses more resources than necessary.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.2.12

digium asterisk 1.2.12.1

digium asterisk 1.2.10

digium asterisk 1.2.11

digium asterisk 1.4.0_beta1

digium asterisk 1.4.0_beta2

digium asterisk 1.2.6

digium asterisk 1.2.7

digium asterisk 1.2.8

digium asterisk 1.2.0_beta1

digium asterisk 1.2.0_beta2

digium asterisk 1.2.9

digium asterisk 1.4.0

Vendor Advisories

Debian Bug report logs - #395080 CVE-2006-5445: Denial of service in chan_sip Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Tue, 24 Oct 2006 20: ...