CVE Database
/

CVE-2014-2287

Back to search

CVE-2014-2287

Published: Apr 18, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

VendorProductVersions

n/a

n/a

affected
n/a

References

66094
vdb-entry
x_refsource_BID
MDVSA-2014:078
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2014-3762
vendor-advisory
x_refsource_FEDORA
FEDORA-2014-3779
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now