Описание
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:digium:asterisk:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.3.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.4.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.5.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:12.5.0:rc1:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00795
Низкий
4 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
ubuntu
около 11 лет назад
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.
debian
около 11 лет назад
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 ...
github
больше 3 лет назад
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.
EPSS
Процентиль: 74%
0.00795
Низкий
4 Medium
CVSS2
Дефекты
CWE-20