Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-2287

Опубликовано: 18 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5

Описание

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

РелизСтатусПримечание
artful

not-affected

1:11.8.1~dfsg-1ubuntu1
bionic

not-affected

1:11.8.1~dfsg-1ubuntu1
cosmic

not-affected

1:11.8.1~dfsg-1ubuntu1
devel

not-affected

1:11.8.1~dfsg-1ubuntu1
disco

not-affected

1:11.8.1~dfsg-1ubuntu1
esm-apps/bionic

not-affected

1:11.8.1~dfsg-1ubuntu1
esm-apps/xenial

not-affected

1:11.8.1~dfsg-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
lucid

ignored

end of life
precise

ignored

end of life

Показывать по

EPSS

Процентиль: 90%
0.05216
Низкий

3.5 Low

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

debian
почти 12 лет назад

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11. ...

github
больше 3 лет назад

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

EPSS

Процентиль: 90%
0.05216
Низкий

3.5 Low

CVSS2