CVE-2014-8416
24.11.2014, 15:59
Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_refer module, allows remote attackers to cause a denial of service (crash) via an in-dialog INVITE with Replaces message, which triggers the channel to be hung up.Enginsight
Vendor | Product | Version |
---|---|---|
digium | asterisk | 12.0.0 ≤ 𝑥 < 12.7.1 |
digium | asterisk | 13.0.0 ≤ 𝑥 < 13.0.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration