CVE Database
/

CVE-2015-3008

Back to search

CVE-2015-3008

Published: Apr 10, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does not properly handle a null byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

VendorProductVersions

n/a

n/a

affected
n/a

References

74022
vdb-entry
x_refsource_BID
MDVSA-2015:206
vendor-advisory
x_refsource_MANDRIVA
1032052
vdb-entry
x_refsource_SECTRACK
DSA-3700
vendor-advisory
x_refsource_DEBIAN
FEDORA-2015-5948
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now