3.5

CVE-2014-2287

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

Data is provided by the National Vulnerability Database (NVD)
DigiumCertified Asterisk Version1.8.0.0 Update-
DigiumCertified Asterisk Version1.8.0.0 Updatebeta1
DigiumCertified Asterisk Version1.8.0.0 Updatebeta2
DigiumCertified Asterisk Version1.8.0.0 Updatebeta3
DigiumCertified Asterisk Version1.8.0.0 Updatebeta4
DigiumCertified Asterisk Version1.8.0.0 Updatebeta5
DigiumCertified Asterisk Version1.8.0.0 Updaterc1
DigiumCertified Asterisk Version1.8.0.0 Updaterc2
DigiumCertified Asterisk Version1.8.0.0 Updaterc3
DigiumCertified Asterisk Version1.8.0.0 Updaterc4
DigiumCertified Asterisk Version1.8.0.0 Updaterc5
DigiumCertified Asterisk Version1.8.1.0 Update-
DigiumCertified Asterisk Version1.8.1.0 Updaterc1
DigiumCertified Asterisk Version1.8.2.0 Update-
DigiumCertified Asterisk Version1.8.2.0 Updaterc1
DigiumCertified Asterisk Version1.8.3.0 Update-
DigiumCertified Asterisk Version1.8.3.0 Updaterc1
DigiumCertified Asterisk Version1.8.3.0 Updaterc2
DigiumCertified Asterisk Version1.8.3.0 Updaterc3
DigiumCertified Asterisk Version1.8.4.0 Update-
DigiumCertified Asterisk Version1.8.4.0 Updaterc1
DigiumCertified Asterisk Version1.8.4.0 Updaterc2
DigiumCertified Asterisk Version1.8.4.0 Updaterc3
DigiumCertified Asterisk Version1.8.5.0 Update-
DigiumCertified Asterisk Version1.8.5.0 Updaterc1
DigiumCertified Asterisk Version1.8.6.0 Update-
DigiumCertified Asterisk Version1.8.6.0 Updaterc1
DigiumCertified Asterisk Version1.8.6.0 Updaterc2
DigiumCertified Asterisk Version1.8.6.0 Updaterc3
DigiumCertified Asterisk Version1.8.7.0 Update-
DigiumCertified Asterisk Version1.8.7.0 Updaterc1
DigiumCertified Asterisk Version1.8.7.0 Updaterc2
DigiumCertified Asterisk Version1.8.8.0 Update-
DigiumCertified Asterisk Version1.8.8.0 Updaterc1
DigiumCertified Asterisk Version1.8.8.0 Updaterc2
DigiumCertified Asterisk Version1.8.8.0 Updaterc3
DigiumCertified Asterisk Version1.8.8.0 Updaterc4
DigiumCertified Asterisk Version1.8.8.0 Updaterc5
DigiumCertified Asterisk Version1.8.9.0 Update-
DigiumCertified Asterisk Version1.8.9.0 Updaterc1
DigiumCertified Asterisk Version1.8.9.0 Updaterc2
DigiumCertified Asterisk Version1.8.9.0 Updaterc3
DigiumCertified Asterisk Version1.8.10.0 Update-
DigiumCertified Asterisk Version1.8.10.0 Updaterc1
DigiumCertified Asterisk Version1.8.10.0 Updaterc2
DigiumCertified Asterisk Version1.8.10.0 Updaterc3
DigiumCertified Asterisk Version1.8.10.0 Updaterc4
DigiumCertified Asterisk Version1.8.11.0 Update-
DigiumCertified Asterisk Version1.8.11.0 Updaterc1
DigiumCertified Asterisk Version1.8.11.0 Updaterc2
DigiumCertified Asterisk Version1.8.11.0 Updaterc3
DigiumCertified Asterisk Version1.8.12.0 Update-
DigiumCertified Asterisk Version1.8.12.0 Updaterc1
DigiumCertified Asterisk Version1.8.12.0 Updaterc2
DigiumCertified Asterisk Version1.8.12.0 Updaterc3
DigiumCertified Asterisk Version1.8.13.0 Update-
DigiumCertified Asterisk Version1.8.13.0 Updaterc1
DigiumCertified Asterisk Version1.8.13.0 Updaterc2
DigiumCertified Asterisk Version1.8.14.0 Updaterc1
DigiumCertified Asterisk Version1.8.14.0 Updaterc2
DigiumCertified Asterisk Version1.8.15 Update-
DigiumCertified Asterisk Version1.8.15 Updatecert1
DigiumCertified Asterisk Version1.8.15 Updatecert1_rc1
DigiumCertified Asterisk Version1.8.15 Updatecert1_rc2
DigiumCertified Asterisk Version1.8.15 Updatecert1_rc3
DigiumCertified Asterisk Version1.8.15 Updatecert2
DigiumCertified Asterisk Version1.8.15 Updatecert3
DigiumCertified Asterisk Version1.8.15 Updatecert4
DigiumCertified Asterisk Version11.6 Updatecert1
DigiumCertified Asterisk Version11.6 Updatecert1_rc1
DigiumCertified Asterisk Version11.6 Updatecert1_rc2
DigiumCertified Asterisk Version11.6.0 Update-
DigiumCertified Asterisk Version11.6.0 Updaterc1
DigiumCertified Asterisk Version11.6.0 Updaterc2
DigiumAsterisk Version1.8.0
DigiumAsterisk Version1.8.0 Updatebeta1
DigiumAsterisk Version1.8.0 Updatebeta2
DigiumAsterisk Version1.8.0 Updatebeta3
DigiumAsterisk Version1.8.0 Updatebeta4
DigiumAsterisk Version1.8.0 Updatebeta5
DigiumAsterisk Version1.8.0 Updaterc2
DigiumAsterisk Version1.8.0 Updaterc3
DigiumAsterisk Version1.8.0 Updaterc4
DigiumAsterisk Version1.8.0 Updaterc5
DigiumAsterisk Version1.8.1
DigiumAsterisk Version1.8.1 Updaterc1
DigiumAsterisk Version1.8.1.1
DigiumAsterisk Version1.8.1.2
DigiumAsterisk Version1.8.2
DigiumAsterisk Version1.8.2.1
DigiumAsterisk Version1.8.2.2
DigiumAsterisk Version1.8.2.3
DigiumAsterisk Version1.8.2.4
DigiumAsterisk Version1.8.3
DigiumAsterisk Version1.8.3 Updaterc1
DigiumAsterisk Version1.8.3 Updaterc2
DigiumAsterisk Version1.8.3 Updaterc3
DigiumAsterisk Version1.8.3.1
DigiumAsterisk Version1.8.3.2
DigiumAsterisk Version1.8.3.3
DigiumAsterisk Version1.8.4
DigiumAsterisk Version1.8.4 Updaterc1
DigiumAsterisk Version1.8.4 Updaterc2
DigiumAsterisk Version1.8.4 Updaterc3
DigiumAsterisk Version1.8.4.1
DigiumAsterisk Version1.8.4.2
DigiumAsterisk Version1.8.4.3
DigiumAsterisk Version1.8.4.4
DigiumAsterisk Version1.8.5
DigiumAsterisk Version1.8.5 Updaterc1
DigiumAsterisk Version1.8.5.0
DigiumAsterisk Version1.8.6.0
DigiumAsterisk Version1.8.6.0 Updaterc1
DigiumAsterisk Version1.8.6.0 Updaterc2
DigiumAsterisk Version1.8.6.0 Updaterc3
DigiumAsterisk Version1.8.7.0
DigiumAsterisk Version1.8.7.0 Updaterc1
DigiumAsterisk Version1.8.7.0 Updaterc2
DigiumAsterisk Version1.8.7.1
DigiumAsterisk Version1.8.8.0
DigiumAsterisk Version1.8.8.0 Update-
DigiumAsterisk Version1.8.8.0 Updatepatch
DigiumAsterisk Version1.8.8.0 Updaterc1
DigiumAsterisk Version1.8.8.0 Updaterc2
DigiumAsterisk Version1.8.8.0 Updaterc3
DigiumAsterisk Version1.8.8.0 Updaterc4
DigiumAsterisk Version1.8.8.0 Updaterc5
DigiumAsterisk Version1.8.8.1
DigiumAsterisk Version1.8.8.2
DigiumAsterisk Version1.8.9.0
DigiumAsterisk Version1.8.9.0 Update-
DigiumAsterisk Version1.8.9.0 Updaterc1
DigiumAsterisk Version1.8.9.0 Updaterc2
DigiumAsterisk Version1.8.9.0 Updaterc3
DigiumAsterisk Version1.8.9.1
DigiumAsterisk Version1.8.9.2
DigiumAsterisk Version1.8.9.3
DigiumAsterisk Version1.8.10.0
DigiumAsterisk Version1.8.10.0 Update-
DigiumAsterisk Version1.8.10.0 Updaterc1
DigiumAsterisk Version1.8.10.0 Updaterc2
DigiumAsterisk Version1.8.10.0 Updaterc3
DigiumAsterisk Version1.8.10.0 Updaterc4
DigiumAsterisk Version1.8.10.1
DigiumAsterisk Version1.8.11.0
DigiumAsterisk Version1.8.11.0 Update-
DigiumAsterisk Version1.8.11.0 Updatepatch
DigiumAsterisk Version1.8.11.0 Updaterc2
DigiumAsterisk Version1.8.11.0 Updaterc3
DigiumAsterisk Version1.8.11.1
DigiumAsterisk Version1.8.11.1 Update-
DigiumAsterisk Version1.8.11.1 Updatepatch
DigiumAsterisk Version1.8.12
DigiumAsterisk Version1.8.12.0
DigiumAsterisk Version1.8.12.0 Update-
DigiumAsterisk Version1.8.12.0 Updaterc1
DigiumAsterisk Version1.8.12.0 Updaterc2
DigiumAsterisk Version1.8.12.0 Updaterc3
DigiumAsterisk Version1.8.12.1
DigiumAsterisk Version1.8.12.2
DigiumAsterisk Version1.8.13.0
DigiumAsterisk Version1.8.13.0 Updaterc1
DigiumAsterisk Version1.8.13.0 Updaterc2
DigiumAsterisk Version1.8.13.1
DigiumAsterisk Version1.8.14.0 Update-
DigiumAsterisk Version1.8.14.0 Updatepatch
DigiumAsterisk Version1.8.14.0 Updaterc1
DigiumAsterisk Version1.8.14.0 Updaterc2
DigiumAsterisk Version1.8.14.1
DigiumAsterisk Version1.8.14.1 Update-
DigiumAsterisk Version1.8.14.1 Updatepatch
DigiumAsterisk Version1.8.15.0
DigiumAsterisk Version1.8.15.0 Update-
DigiumAsterisk Version1.8.15.0 Updaterc1
DigiumAsterisk Version1.8.15.1
DigiumAsterisk Version1.8.16.0
DigiumAsterisk Version1.8.16.0 Update-
DigiumAsterisk Version1.8.16.0 Updaterc1
DigiumAsterisk Version1.8.16.0 Updaterc2
DigiumAsterisk Version1.8.17.0
DigiumAsterisk Version1.8.17.0 Update-
DigiumAsterisk Version1.8.17.0 Updatepatch
DigiumAsterisk Version1.8.17.0 Updaterc1
DigiumAsterisk Version1.8.17.0 Updaterc2
DigiumAsterisk Version1.8.17.0 Updaterc3
DigiumAsterisk Version1.8.18.0
DigiumAsterisk Version1.8.18.0 Update-
DigiumAsterisk Version1.8.18.0 Updaterc1
DigiumAsterisk Version1.8.18.1
DigiumAsterisk Version1.8.19.0
DigiumAsterisk Version1.8.19.0 Update-
DigiumAsterisk Version1.8.19.0 Updaterc1
DigiumAsterisk Version1.8.19.0 Updaterc3
DigiumAsterisk Version1.8.19.1
DigiumAsterisk Version1.8.20.0 Update-
DigiumAsterisk Version1.8.20.0 Updatepatch
DigiumAsterisk Version1.8.20.0 Updaterc1
DigiumAsterisk Version1.8.20.0 Updaterc2
DigiumAsterisk Version1.8.20.1 Update-
DigiumAsterisk Version1.8.20.1 Updatepatch
DigiumAsterisk Version1.8.20.2 Update-
DigiumAsterisk Version1.8.20.2 Updatepatch
DigiumAsterisk Version1.8.21.0 Update-
DigiumAsterisk Version1.8.21.0 Updaterc1
DigiumAsterisk Version1.8.21.0 Updaterc2
DigiumAsterisk Version1.8.22.0 Update-
DigiumAsterisk Version1.8.22.0 Updaterc1
DigiumAsterisk Version1.8.22.0 Updaterc2
DigiumAsterisk Version1.8.23.0 Update-
DigiumAsterisk Version1.8.23.0 Updatepatch
DigiumAsterisk Version1.8.23.0 Updaterc1
DigiumAsterisk Version1.8.23.0 Updaterc2
DigiumAsterisk Version1.8.23.1
DigiumAsterisk Version1.8.24.0 Update-
DigiumAsterisk Version1.8.24.0 Updaterc1
DigiumAsterisk Version1.8.24.0 Updaterc2
DigiumAsterisk Version1.8.24.1
DigiumAsterisk Version1.8.25.0 Update-
DigiumAsterisk Version1.8.25.0 Updaterc1
DigiumAsterisk Version1.8.25.0 Updaterc2
DigiumAsterisk Version1.8.26.0 Update-
DigiumAsterisk Version1.8.26.0 Updaterc1
DigiumAsterisk Version11.8.0 Update-
DigiumAsterisk Version11.8.0 Updaterc1
DigiumAsterisk Version11.8.0 Updaterc2
DigiumAsterisk Version11.8.0 Updaterc3
DigiumAsterisk Version12.1.0 Update-
DigiumAsterisk Version12.1.0 Updaterc1
DigiumAsterisk Version12.1.0 Updaterc2
DigiumAsterisk Version12.1.0 Updaterc3
FedoraprojectFedora Version19
FedoraprojectFedora Version20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 22.86% 0.957
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.