Description
reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.
References (9)
Core 9
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/518236/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44828
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062658.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062013.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1025598
Vendor Advisory x_refsource_confirm
http://downloads.digium.com/pub/security/AST-2011-007.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/72752
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48096
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67812
Scores
EPSS
0.0462
EPSS Percentile
90.7%
Details
Status
published
Products (15)
digium/asterisk
1.8.0 (10 CPE variants)
digium/asterisk
1.8.1 (2 CPE variants)
digium/asterisk
1.8.1.1
digium/asterisk
1.8.1.2
digium/asterisk
1.8.2
digium/asterisk
1.8.2.1
digium/asterisk
1.8.2.2
digium/asterisk
1.8.2.3
digium/asterisk
1.8.2.4
digium/asterisk
1.8.3 (4 CPE variants)
... and 5 more
Published
Jun 06, 2011
Tracked Since
Feb 18, 2026