[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-3863Date: (C)2012-07-09   (M)2023-12-22


channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Asterisk Business Edition C.3.x before C.3.7.5, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digiumphones does not properly handle a provisional response to a SIP reINVITE request, which allows remote authenticated users to cause a denial of service (RTP port exhaustion) via sessions that lack final responses.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.0
Exploit Score: 8.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECUNIA-50687
SECUNIA-50756
BID-54327
DSA-2550
http://downloads.asterisk.org/pub/security/AST-2012-010.html
https://issues.asterisk.org/jira/browse/ASTERISK-19992

CPE    126
cpe:/a:digium:asterisk:10.2.0:rc2:digiumphones
cpe:/a:digium:asterisk:10.4.0:rc2
cpe:/a:digium:asterisk:10.4.0:rc1
cpe:/a:digium:asterisk:10.4.0:rc3
...
CWE    1
CWE-399
OVAL    3
oval:org.secpod.oval:def:103994
oval:org.secpod.oval:def:600894
oval:org.secpod.oval:def:600890

© SecPod Technologies