3.5
CVSSv2

CVE-2015-1558

Published: 09/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

Asterisk Open Source 12.x prior to 12.8.1 and 13.x prior to 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 12.0.0

digium asterisk 12.2.0

digium asterisk 12.4.0

digium asterisk 12.5.0

digium asterisk 12.8.0

digium asterisk 13.2.0

digium asterisk 12.1.0

digium asterisk 12.3.0

digium asterisk 12.6.0

digium asterisk 12.7.0

digium asterisk 13.0.0

digium asterisk 13.1.0

digium asterisk 12.1.1

digium asterisk 12.3.1

digium asterisk 12.3.2

digium asterisk 12.8.1

Vendor Advisories

Debian Bug report logs - #780601 asterisk: CVE-2015-1558: File descriptor leak when incompatible codecs are offered Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 16 Mar 2015 15:27:0 ...