5

CVE-2013-5642

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.3-digiumphones allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and daemon crash) via an invalid SDP that defines a media description before the connection description in a SIP request.

Data is provided by the National Vulnerability Database (NVD)
DigiumAsterisk Version1.8.17.0
DigiumAsterisk Version1.8.17.0 Updaterc1
DigiumAsterisk Version1.8.17.0 Updaterc2
DigiumAsterisk Version1.8.17.0 Updaterc3
DigiumAsterisk Version1.8.18.0
DigiumAsterisk Version1.8.18.0 Updaterc1
DigiumAsterisk Version1.8.18.1
DigiumAsterisk Version1.8.19.0
DigiumAsterisk Version1.8.19.0 Updaterc1
DigiumAsterisk Version1.8.19.0 Updaterc3
DigiumAsterisk Version1.8.19.1
DigiumAsterisk Version1.8.20.0
DigiumAsterisk Version1.8.20.0 Updaterc1
DigiumAsterisk Version1.8.20.0 Updaterc2
DigiumAsterisk Version1.8.21.0 Updaterc1
DigiumAsterisk Version1.8.21.0 Updaterc2
DigiumAsterisk Version1.8.22.0
DigiumAsterisk Version1.8.22.0 Updaterc1
DigiumAsterisk Version1.8.22.0 Updaterc2
DigiumAsterisk Version1.8.23.0
DigiumAsterisk Version1.8.23.0 Updaterc1
DigiumAsterisk Version1.8.23.0 Updaterc2
DigiumAsterisk Version10.10.0
DigiumAsterisk Version10.10.0 Updaterc1
DigiumAsterisk Version10.10.0 Updaterc2
DigiumAsterisk Version10.11.0
DigiumAsterisk Version10.11.0 Updaterc1
DigiumAsterisk Version10.11.0 Updaterc2
DigiumAsterisk Version10.11.0 Updaterc3
DigiumAsterisk Version10.12.0
DigiumAsterisk Version10.12.0 Updaterc1
DigiumAsterisk Version10.12.0 Updaterc2
DigiumAsterisk Version10.12.1
DigiumAsterisk Version10.12.2
DigiumAsterisk Version11.0.0
DigiumAsterisk Version11.0.0 Updatebeta1
DigiumAsterisk Version11.0.0 Updatebeta2
DigiumAsterisk Version11.0.0 Updaterc1
DigiumAsterisk Version11.0.0 Updaterc2
DigiumAsterisk Version11.0.1
DigiumAsterisk Version11.0.2
DigiumAsterisk Version11.1.0
DigiumAsterisk Version11.1.0 Updaterc1
DigiumAsterisk Version11.1.0 Updaterc3
DigiumAsterisk Version11.1.1
DigiumAsterisk Version11.1.2
DigiumAsterisk Version11.2.0 Updaterc1
DigiumAsterisk Version11.2.0 Updaterc2
DigiumAsterisk Version11.3.0 Updaterc1
DigiumAsterisk Version11.3.0 Updaterc2
DigiumAsterisk Version11.4.0
DigiumAsterisk Version11.4.0 Updaterc1
DigiumAsterisk Version11.4.0 Updaterc2
DigiumAsterisk Version11.4.0 Updaterc3
DigiumAsterisk Version11.5.0
DigiumAsterisk Version11.5.0 Updaterc1
DigiumAsterisk Version11.5.0 Updaterc2
DigiumAsterisk Version11.5.1
DigiumAsterisk Digiumphones Version10.0.0
DigiumAsterisk Digiumphones Version10.0.0 Updaterc1
DigiumAsterisk Digiumphones Version10.0.0 Updaterc2
DigiumAsterisk Digiumphones Version10.11.0
DigiumAsterisk Digiumphones Version10.11.0 Updaterc1
DigiumAsterisk Digiumphones Version10.11.0 Updaterc2
DigiumAsterisk Digiumphones Version10.11.0 Updaterc3
DigiumAsterisk Digiumphones Version10.12.0
DigiumAsterisk Digiumphones Version10.12.0 Updaterc1
DigiumAsterisk Digiumphones Version10.12.0 Updaterc2
DigiumAsterisk Digiumphones Version10.12.1
DigiumAsterisk Digiumphones Version10.12.2
DigiumCertified Asterisk Version1.8.15
DigiumCertified Asterisk Version1.8.15 Updatecert1
DigiumCertified Asterisk Version1.8.15 Updatecert1-rc1
DigiumCertified Asterisk Version1.8.15 Updatecert1-rc2
DigiumCertified Asterisk Version1.8.15 Updatecert1-rc3
DigiumCertified Asterisk Version1.8.15 Updatecert2
DigiumCertified Asterisk Version1.8.15 Updaterc1
DigiumCertified Asterisk Version11.2.0
DigiumCertified Asterisk Version11.2.0 Updatecert1
DigiumCertified Asterisk Version11.2.0 Updaterc1
DigiumCertified Asterisk Version11.2.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.08% 0.894
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.