4
CVSSv2

CVE-2014-6609

Published: 26/11/2014 Updated: 26/11/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The res_pjsip_pubsub module in Asterisk Open Source 12.x prior to 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 12.2.0

digium asterisk 12.1.0

digium asterisk 12.5.0

digium asterisk 12.4.0

digium asterisk 12.3.0

digium asterisk 12.0.0