3.5
CVSSv2

CVE-2009-0871

Published: 11/03/2009 Updated: 10/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 prior to 1.6.0.6; 1.6.1 prior to 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk c.2.3

digium asterisk 1.6.0

digium asterisk 1.6.0.3

digium asterisk 1.6.1

digium asterisk 1.4.22

digium asterisk 1.6.0.4

digium asterisk 1.6.0.5

digium asterisk 1.4.23

digium asterisk 1.4.23.1

digium asterisk 1.6.0.1

digium asterisk 1.6.0.2