5
CVSSv2

CVE-2011-2216

Published: 06/06/2011 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x prior to 1.8.4.2 does not initialize certain strings, which allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.8.1

digium asterisk 1.8.0

digium asterisk 1.8.3

digium asterisk 1.8.3.1

digium asterisk 1.8.4

digium asterisk 1.8.2.3

digium asterisk 1.8.2.2

digium asterisk 1.8.2.1

digium asterisk 1.8.2

digium asterisk 1.8.3.2

digium asterisk 1.8.2.4

digium asterisk 1.8.4.1

digium asterisk 1.8.1.2

digium asterisk 1.8.1.1

digium asterisk 1.8.3.3

Vendor Advisories

Debian Bug report logs - #629130 AST-2011-007 remote crash in SIP driver Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Fri, 3 Jun 2011 18: ...