4.3

CVE-2008-2119

Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AsteriskAsterisk Business Edition Version <= b2.5.2
AsteriskAsterisk Business Edition Versionb.1.3.2
AsteriskAsterisk Business Edition Versionb.1.3.3
AsteriskAsterisk Business Edition Versionb.2.2.0
AsteriskAsterisk Business Edition Versionb.2.2.1
AsteriskAsterisk Business Edition Versionb.2.3.1
AsteriskAsterisk Business Edition Versionb.2.3.2
AsteriskAsterisk Business Edition Versionb.2.3.3
AsteriskAsterisk Business Edition Versionb.2.3.4
AsteriskAsterisk Business Edition Versionb.2.5.0
AsteriskOpen Source Version <= 1.2.28
AsteriskOpen Source Version1.0
AsteriskOpen Source Version1.0.0
AsteriskOpen Source Version1.0.1
AsteriskOpen Source Version1.0.2
AsteriskOpen Source Version1.0.3
AsteriskOpen Source Version1.0.4
AsteriskOpen Source Version1.0.5
AsteriskOpen Source Version1.0.6
AsteriskOpen Source Version1.0.7
AsteriskOpen Source Version1.0.8
AsteriskOpen Source Version1.0.9
AsteriskOpen Source Version1.0.11
AsteriskOpen Source Version1.0.11.1
AsteriskOpen Source Version1.0.12
AsteriskOpen Source Version1.2.0
AsteriskOpen Source Version1.2.0beta1
AsteriskOpen Source Version1.2.0beta2
AsteriskOpen Source Version1.2.1
AsteriskOpen Source Version1.2.2
AsteriskOpen Source Version1.2.10
AsteriskOpen Source Version1.2.11
AsteriskOpen Source Version1.2.12
AsteriskOpen Source Version1.2.12.1
AsteriskOpen Source Version1.2.13
AsteriskOpen Source Version1.2.14
AsteriskOpen Source Version1.2.15
AsteriskOpen Source Version1.2.16
AsteriskOpen Source Version1.2.17
AsteriskOpen Source Version1.2.18
AsteriskOpen Source Version1.2.19
AsteriskOpen Source Version1.2.20
AsteriskOpen Source Version1.2.21
AsteriskOpen Source Version1.2.21.1
AsteriskOpen Source Version1.2.22
AsteriskOpen Source Version1.2.23
AsteriskOpen Source Version1.2.24
AsteriskOpen Source Version1.2.25
AsteriskOpen Source Version1.2.26
AsteriskOpen Source Version1.2.26.1
AsteriskOpen Source Version1.2.26.2
AsteriskOpen Source Version1.2.27
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.1% 0.938
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.