Back to search
CVE-2014-2286
Published: Apr 18, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://issues.asterisk.org/jira/browse/ASTERISK-23340
x_refsource_CONFIRM
http://downloads.asterisk.org/pub/security/AST-2014-001-1.8.diff
x_refsource_MISC
http://downloads.asterisk.org/pub/security/AST-2014-001.html
x_refsource_CONFIRM
66093
vdb-entry
x_refsource_BID
MDVSA-2014:078
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2014-3762
vendor-advisory
x_refsource_FEDORA
FEDORA-2014-3779
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now