CVE Database
/

CVE-2013-5642

Back to search

CVE-2013-5642

Published: Sep 9, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.3-digiumphones allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and daemon crash) via an invalid SDP that defines a media description before the connection description in a SIP request.

VendorProductVersions

n/a

n/a

affected
n/a

References

54534
third-party-advisory
x_refsource_SECUNIA
96690
vdb-entry
x_refsource_OSVDB
54617
third-party-advisory
x_refsource_SECUNIA
DSA-2749
vendor-advisory
x_refsource_DEBIAN
1028957
vdb-entry
x_refsource_SECTRACK
62022
vdb-entry
x_refsource_BID
MDVSA-2013:223
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now