CVE-2014-4045
17.06.2014, 14:55
The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_expiry is set to zero, allows remote attackers to cause a denial of service (assertion failure and crash) via an unsubscribe request when not subscribed to the device.Enginsight
Vendor | Product | Version |
---|---|---|
digium | asterisk | 12.0.0 |
digium | asterisk | 12.1.0 |
digium | asterisk | 12.1.0:rc1 |
digium | asterisk | 12.1.0:rc2 |
digium | asterisk | 12.1.0:rc3 |
digium | asterisk | 12.1.1 |
digium | asterisk | 12.2.0 |
digium | asterisk | 12.2.0:rc1 |
digium | asterisk | 12.2.0:rc2 |
digium | asterisk | 12.2.0:rc3 |
digium | asterisk | 12.3.0 |
digium | asterisk | 12.3.0:rc1 |
digium | asterisk | 12.3.0:rc2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References