4
CVSSv2

CVE-2012-3863

Published: 09/07/2012 Updated: 10/10/2013
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

channels/chan_sip.c in Asterisk Open Source 1.8.x prior to 1.8.13.1 and 10.x prior to 10.5.2, Asterisk Business Edition C.3.x before C.3.7.5, Certified Asterisk 1.8.11-certx prior to 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones prior to 10.5.2-digiumphones does not properly handle a provisional response to a SIP reINVITE request, which allows remote authenticated users to cause a denial of service (RTP port exhaustion) via sessions that lack final responses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk business edition c.3.1

digium asterisk business edition c.3.7.4

digium asterisk business edition c.3.3

digium asterisk 1.8.0

digium asterisk 1.8.1

digium asterisk 1.8.2.3

digium asterisk 1.8.3

digium asterisk 1.8.4.1

digium asterisk 1.8.4.2

digium asterisk 1.8.6.0

digium asterisk 1.8.8.0

digium asterisk 1.8.9.2

digium asterisk 1.8.9.0

digium asterisk 1.8.11.0

digium asterisk 1.8.11.1

digium asterisk 1.8.1.2

digium asterisk 1.8.1.1

digium asterisk 1.8.3.2

digium asterisk 1.8.4

digium asterisk 1.8.7.0

digium asterisk 1.8.7.1

digium certified asterisk 1.8.11

digium asterisk 1.8.2.1

digium asterisk 1.8.2

digium asterisk 1.8.2.4

digium asterisk 1.8.3.3

digium asterisk 1.8.4.4

digium asterisk 1.8.5

digium asterisk 1.8.5.0

digium asterisk 1.8.8.1

digium asterisk 1.8.8.2

digium asterisk 1.8.13.0

digium asterisk 1.8.2.2

digium asterisk 1.8.3.1

digium asterisk 1.8.4.3

digium asteriske 1.8.8.0

digium asteriske 1.8.9.1

digium asterisk 1.8.9.3

digium asterisk 10.5.0

digium asterisk 10.4.0

digium asterisk 10.3.0

digium asterisk 10.1.0

digium asterisk 10.0.0

digium asterisk 10.2.0

digium asterisk 10.5.1

digium asterisk 10.3.1

digium asterisk 10.4.1

digium asterisk 10.0.1

digium asterisk 10.2.1

digium asterisk 10.1.3

digium asterisk 10.1.2

digium asterisk 10.4.2

digium asterisk 10.1.1

Vendor Advisories

Debian Bug report logs - #680470 Two security issues: AST-2012-010 / AST-2012-011 Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: F ...