Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-2286

Опубликовано: 18 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5

Описание

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.

РелизСтатусПримечание
artful

not-affected

1:11.8.1~dfsg-1ubuntu1
bionic

not-affected

1:11.8.1~dfsg-1ubuntu1
cosmic

not-affected

1:11.8.1~dfsg-1ubuntu1
devel

not-affected

1:11.8.1~dfsg-1ubuntu1
disco

not-affected

1:11.8.1~dfsg-1ubuntu1
esm-apps/bionic

not-affected

1:11.8.1~dfsg-1ubuntu1
esm-apps/xenial

not-affected

1:11.8.1~dfsg-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
lucid

ignored

end of life
precise

ignored

end of life

Показывать по

EPSS

Процентиль: 94%
0.14756
Средний

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.

debian
почти 12 лет назад

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x befo ...

github
больше 3 лет назад

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.

EPSS

Процентиль: 94%
0.14756
Средний

7.5 High

CVSS2