5
CVSSv2

CVE-2014-9374

Published: 12/12/2014 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x prior to 11.14.2, 12.x prior to 12.7.2, and 13.x prior to 13.0.2 and Certified Asterisk 11.6 prior to 11.6-cert9 allows remote malicious users to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame.

Vulnerable Product Search on Vulmon Subscribe to Product

digium certified asterisk 11.6

digium certified asterisk 11.6.0

digium asterisk 12.7.0

digium asterisk 12.4.0

digium asterisk 13.0.0

digium asterisk 12.7.1

digium asterisk 12.5.0

digium asterisk 12.2.0

digium asterisk 12.1.0

digium asterisk 11.14.0

digium asterisk 11.13.0

digium asterisk 11.10.0

digium asterisk 11.9.0

digium asterisk 11.8.0

digium asterisk 11.7.0

digium asterisk 11.5.0

digium asterisk 11.4.0

digium asterisk 11.2.0

digium asterisk 11.0.0

digium asterisk 12.3.0

digium asterisk 11.12.0

digium asterisk 11.6.0

digium asterisk 11.1.0

digium asterisk 12.6.0

digium asterisk 12.0.0

digium asterisk 11.11.0

digium asterisk 13.0.1

digium asterisk 11.3.0

Vendor Advisories

Debian Bug report logs - #771463 CVE-2014-8418 CVE-2014-8412 CVE-2014-8414 CVE-2014-8417 Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 29 Nov 2014 21:36:01 UTC Severity: grave Tags: sec ...
Debian Bug report logs - #773230 asterisk: CVE-2014-9374 Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 15 Dec 2014 20:30:02 UTC Severity: important Tags: fixed-upstream, security, ...