Record summary

CVE-2008-2119 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAsterisk 1.2.x - SIP channel driver / in pedantic mode Remote CrashExploitDB exploitby Armando OliveiraNot analyzed1 file
ExploitDB

PoC details

References

12