6.8
CVSSv2

CVE-2011-4063

Published: 21/10/2011 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x prior to 1.8.7.1 and 10.x prior to 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authenticated users to cause a denial of service (daemon crash) via a malformed request.

Vulnerable Product Search on Vulmon Subscribe to Product

asterisk open source 1.8.7

asterisk open source 10.0.0

Vendor Advisories

Debian Bug report logs - #647252 CVE-2011-4063: Remote crash vulnerability in SIP channel driver Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentiond ...