4
CVSSv2

CVE-2014-6610

Published: 26/11/2014 Updated: 26/11/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Asterisk Open Source 11.x prior to 11.12.1 and 12.x prior to 12.5.1 and Certified Asterisk 11.6 prior to 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.

Vulnerable Product Search on Vulmon Subscribe to Product

digium certified asterisk 11.6.0

digium certified asterisk 11.6

digium asterisk 12.5.0

digium asterisk 12.4.0

digium asterisk 12.0.0

digium asterisk 11.12.0

digium asterisk 11.11.0

digium asterisk 11.6.0

digium asterisk 11.5.0

digium asterisk 11.1.0

digium asterisk 11.0.0

digium asterisk 12.2.0

digium asterisk 11.9.0

digium asterisk 11.8.0

digium asterisk 11.4.0

digium asterisk 11.3.0

digium asterisk 12.3.0

digium asterisk 12.1.0

digium asterisk 11.10.0

digium asterisk 11.7.0

digium asterisk 11.2.0

Vendor Advisories

Debian Bug report logs - #762164 asterisk: CVE-2014-6610: Remote crash when handling out of call message in certain dialplan configurations Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...