Lucene search

K
cve[email protected]CVE-2014-2286
HistoryApr 18, 2014 - 10:14 p.m.

CVE-2014-2286

2014-04-1822:14:37
CWE-20
web.nvd.nist.gov
43
cve-2014-2286
asterisk
open source
certified asterisk
denial of service
stack consumption
remote attack
arbitrary code execution
http header
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.599 Medium

EPSS

Percentile

97.8%

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.

Affected configurations

NVD
Node
digiumasteriskMatch1.8.0
OR
digiumasteriskMatch1.8.0beta1
OR
digiumasteriskMatch1.8.0beta2
OR
digiumasteriskMatch1.8.0beta3
OR
digiumasteriskMatch1.8.0beta4
OR
digiumasteriskMatch1.8.0beta5
OR
digiumasteriskMatch1.8.0rc2
OR
digiumasteriskMatch1.8.0rc3
OR
digiumasteriskMatch1.8.0rc4
OR
digiumasteriskMatch1.8.0rc5
OR
digiumasteriskMatch1.8.1
OR
digiumasteriskMatch1.8.1rc1
OR
digiumasteriskMatch1.8.1.1
OR
digiumasteriskMatch1.8.1.2
OR
digiumasteriskMatch1.8.2
OR
digiumasteriskMatch1.8.2.1
OR
digiumasteriskMatch1.8.2.2
OR
digiumasteriskMatch1.8.2.3
OR
digiumasteriskMatch1.8.2.4
OR
digiumasteriskMatch1.8.3
OR
digiumasteriskMatch1.8.3rc1
OR
digiumasteriskMatch1.8.3rc2
OR
digiumasteriskMatch1.8.3rc3
OR
digiumasteriskMatch1.8.3.1
OR
digiumasteriskMatch1.8.3.2
OR
digiumasteriskMatch1.8.3.3
OR
digiumasteriskMatch1.8.4
OR
digiumasteriskMatch1.8.4rc1
OR
digiumasteriskMatch1.8.4rc2
OR
digiumasteriskMatch1.8.4rc3
OR
digiumasteriskMatch1.8.4.1
OR
digiumasteriskMatch1.8.4.2
OR
digiumasteriskMatch1.8.4.3
OR
digiumasteriskMatch1.8.4.4
OR
digiumasteriskMatch1.8.5
OR
digiumasteriskMatch1.8.5rc1
OR
digiumasteriskMatch1.8.5.0
OR
digiumasteriskMatch1.8.6.0
OR
digiumasteriskMatch1.8.6.0rc1
OR
digiumasteriskMatch1.8.6.0rc2
OR
digiumasteriskMatch1.8.6.0rc3
OR
digiumasteriskMatch1.8.7.0
OR
digiumasteriskMatch1.8.7.0rc1
OR
digiumasteriskMatch1.8.7.0rc2
OR
digiumasteriskMatch1.8.7.1
OR
digiumasteriskMatch1.8.8.0
OR
digiumasteriskMatch1.8.8.0-
OR
digiumasteriskMatch1.8.8.0patch
OR
digiumasteriskMatch1.8.8.0rc1
OR
digiumasteriskMatch1.8.8.0rc2
OR
digiumasteriskMatch1.8.8.0rc3
OR
digiumasteriskMatch1.8.8.0rc4
OR
digiumasteriskMatch1.8.8.0rc5
OR
digiumasteriskMatch1.8.8.1
OR
digiumasteriskMatch1.8.8.2
OR
digiumasteriskMatch1.8.9.0
OR
digiumasteriskMatch1.8.9.0-
OR
digiumasteriskMatch1.8.9.0rc1
OR
digiumasteriskMatch1.8.9.0rc2
OR
digiumasteriskMatch1.8.9.0rc3
OR
digiumasteriskMatch1.8.9.1
OR
digiumasteriskMatch1.8.9.2
OR
digiumasteriskMatch1.8.9.3
OR
digiumasteriskMatch1.8.10.0
OR
digiumasteriskMatch1.8.10.0-
OR
digiumasteriskMatch1.8.10.0rc1
OR
digiumasteriskMatch1.8.10.0rc2
OR
digiumasteriskMatch1.8.10.0rc3
OR
digiumasteriskMatch1.8.10.0rc4
OR
digiumasteriskMatch1.8.10.1
OR
digiumasteriskMatch1.8.11.0
OR
digiumasteriskMatch1.8.11.0-
OR
digiumasteriskMatch1.8.11.0patch
OR
digiumasteriskMatch1.8.11.0rc2
OR
digiumasteriskMatch1.8.11.0rc3
OR
digiumasteriskMatch1.8.11.1
OR
digiumasteriskMatch1.8.11.1-
OR
digiumasteriskMatch1.8.11.1patch
OR
digiumasteriskMatch1.8.12
OR
digiumasteriskMatch1.8.12.0
OR
digiumasteriskMatch1.8.12.0-
OR
digiumasteriskMatch1.8.12.0rc1
OR
digiumasteriskMatch1.8.12.0rc2
OR
digiumasteriskMatch1.8.12.0rc3
OR
digiumasteriskMatch1.8.12.1
OR
digiumasteriskMatch1.8.12.2
OR
digiumasteriskMatch1.8.13.0
OR
digiumasteriskMatch1.8.13.0rc1
OR
digiumasteriskMatch1.8.13.0rc2
OR
digiumasteriskMatch1.8.13.1
OR
digiumasteriskMatch1.8.14.0-
OR
digiumasteriskMatch1.8.14.0patch
OR
digiumasteriskMatch1.8.14.0rc1
OR
digiumasteriskMatch1.8.14.0rc2
OR
digiumasteriskMatch1.8.14.1
OR
digiumasteriskMatch1.8.14.1-
OR
digiumasteriskMatch1.8.14.1patch
OR
digiumasteriskMatch1.8.15.0
OR
digiumasteriskMatch1.8.15.0-
OR
digiumasteriskMatch1.8.15.0rc1
OR
digiumasteriskMatch1.8.15.1
OR
digiumasteriskMatch1.8.16.0
OR
digiumasteriskMatch1.8.16.0-
OR
digiumasteriskMatch1.8.16.0rc1
OR
digiumasteriskMatch1.8.16.0rc2
OR
digiumasteriskMatch1.8.17.0
OR
digiumasteriskMatch1.8.17.0-
OR
digiumasteriskMatch1.8.17.0patch
OR
digiumasteriskMatch1.8.17.0rc1
OR
digiumasteriskMatch1.8.17.0rc2
OR
digiumasteriskMatch1.8.17.0rc3
OR
digiumasteriskMatch1.8.18.0
OR
digiumasteriskMatch1.8.18.0-
OR
digiumasteriskMatch1.8.18.0rc1
OR
digiumasteriskMatch1.8.18.1
OR
digiumasteriskMatch1.8.19.0
OR
digiumasteriskMatch1.8.19.0-
OR
digiumasteriskMatch1.8.19.0rc1
OR
digiumasteriskMatch1.8.19.0rc3
OR
digiumasteriskMatch1.8.19.1
OR
digiumasteriskMatch1.8.20.0-
OR
digiumasteriskMatch1.8.20.0patch
OR
digiumasteriskMatch1.8.20.0rc1
OR
digiumasteriskMatch1.8.20.0rc2
OR
digiumasteriskMatch1.8.20.1-
OR
digiumasteriskMatch1.8.20.1patch
OR
digiumasteriskMatch1.8.20.2-
OR
digiumasteriskMatch1.8.20.2patch
OR
digiumasteriskMatch1.8.21.0-
OR
digiumasteriskMatch1.8.21.0rc1
OR
digiumasteriskMatch1.8.21.0rc2
OR
digiumasteriskMatch1.8.22.0-
OR
digiumasteriskMatch1.8.22.0rc1
OR
digiumasteriskMatch1.8.22.0rc2
OR
digiumasteriskMatch1.8.23.0-
OR
digiumasteriskMatch1.8.23.0patch
OR
digiumasteriskMatch1.8.23.0rc1
OR
digiumasteriskMatch1.8.23.0rc2
OR
digiumasteriskMatch1.8.23.1
OR
digiumasteriskMatch1.8.24.0-
OR
digiumasteriskMatch1.8.24.0rc1
OR
digiumasteriskMatch1.8.24.0rc2
OR
digiumasteriskMatch1.8.24.1
OR
digiumasteriskMatch1.8.25.0-
OR
digiumasteriskMatch1.8.25.0rc1
OR
digiumasteriskMatch1.8.25.0rc2
OR
digiumasteriskMatch1.8.26.0-
OR
digiumasteriskMatch1.8.26.0rc1
OR
digiumasteriskMatch11.8.0-
OR
digiumasteriskMatch11.8.0rc1
OR
digiumasteriskMatch11.8.0rc2
OR
digiumasteriskMatch11.8.0rc3
OR
digiumasteriskMatch12.1.0-
OR
digiumasteriskMatch12.1.0rc1
OR
digiumasteriskMatch12.1.0rc2
OR
digiumasteriskMatch12.1.0rc3
OR
fedoraprojectfedoraMatch19
OR
fedoraprojectfedoraMatch20
Node
digiumcertified_asteriskMatch1.8.0.0-
OR
digiumcertified_asteriskMatch1.8.0.0beta1
OR
digiumcertified_asteriskMatch1.8.0.0beta2
OR
digiumcertified_asteriskMatch1.8.0.0beta3
OR
digiumcertified_asteriskMatch1.8.0.0beta4
OR
digiumcertified_asteriskMatch1.8.0.0beta5
OR
digiumcertified_asteriskMatch1.8.0.0rc1
OR
digiumcertified_asteriskMatch1.8.0.0rc2
OR
digiumcertified_asteriskMatch1.8.0.0rc3
OR
digiumcertified_asteriskMatch1.8.0.0rc4
OR
digiumcertified_asteriskMatch1.8.0.0rc5
OR
digiumcertified_asteriskMatch1.8.1.0-
OR
digiumcertified_asteriskMatch1.8.1.0rc1
OR
digiumcertified_asteriskMatch1.8.2.0-
OR
digiumcertified_asteriskMatch1.8.2.0rc1
OR
digiumcertified_asteriskMatch1.8.3.0-
OR
digiumcertified_asteriskMatch1.8.3.0rc1
OR
digiumcertified_asteriskMatch1.8.3.0rc2
OR
digiumcertified_asteriskMatch1.8.3.0rc3
OR
digiumcertified_asteriskMatch1.8.4.0-
OR
digiumcertified_asteriskMatch1.8.4.0rc1
OR
digiumcertified_asteriskMatch1.8.4.0rc2
OR
digiumcertified_asteriskMatch1.8.4.0rc3
OR
digiumcertified_asteriskMatch1.8.5.0-
OR
digiumcertified_asteriskMatch1.8.5.0rc1
OR
digiumcertified_asteriskMatch1.8.6.0-
OR
digiumcertified_asteriskMatch1.8.6.0rc1
OR
digiumcertified_asteriskMatch1.8.6.0rc2
OR
digiumcertified_asteriskMatch1.8.6.0rc3
OR
digiumcertified_asteriskMatch1.8.7.0-
OR
digiumcertified_asteriskMatch1.8.7.0rc1
OR
digiumcertified_asteriskMatch1.8.7.0rc2
OR
digiumcertified_asteriskMatch1.8.8.0-
OR
digiumcertified_asteriskMatch1.8.8.0rc1
OR
digiumcertified_asteriskMatch1.8.8.0rc2
OR
digiumcertified_asteriskMatch1.8.8.0rc3
OR
digiumcertified_asteriskMatch1.8.8.0rc4
OR
digiumcertified_asteriskMatch1.8.8.0rc5
OR
digiumcertified_asteriskMatch1.8.9.0-
OR
digiumcertified_asteriskMatch1.8.9.0rc1
OR
digiumcertified_asteriskMatch1.8.9.0rc2
OR
digiumcertified_asteriskMatch1.8.9.0rc3
OR
digiumcertified_asteriskMatch1.8.10.0-
OR
digiumcertified_asteriskMatch1.8.10.0rc1
OR
digiumcertified_asteriskMatch1.8.10.0rc2
OR
digiumcertified_asteriskMatch1.8.10.0rc3
OR
digiumcertified_asteriskMatch1.8.10.0rc4
OR
digiumcertified_asteriskMatch1.8.11.0-
OR
digiumcertified_asteriskMatch1.8.11.0rc1
OR
digiumcertified_asteriskMatch1.8.11.0rc2
OR
digiumcertified_asteriskMatch1.8.11.0rc3
OR
digiumcertified_asteriskMatch1.8.12.0-
OR
digiumcertified_asteriskMatch1.8.12.0rc1
OR
digiumcertified_asteriskMatch1.8.12.0rc2
OR
digiumcertified_asteriskMatch1.8.12.0rc3
OR
digiumcertified_asteriskMatch1.8.13.0-
OR
digiumcertified_asteriskMatch1.8.13.0rc1
OR
digiumcertified_asteriskMatch1.8.13.0rc2
OR
digiumcertified_asteriskMatch1.8.14.0rc1
OR
digiumcertified_asteriskMatch1.8.14.0rc2
OR
digiumcertified_asteriskMatch1.8.15-
OR
digiumcertified_asteriskMatch1.8.15cert1
OR
digiumcertified_asteriskMatch1.8.15cert1_rc1
OR
digiumcertified_asteriskMatch1.8.15cert1_rc2
OR
digiumcertified_asteriskMatch1.8.15cert1_rc3
OR
digiumcertified_asteriskMatch1.8.15cert2
OR
digiumcertified_asteriskMatch1.8.15cert3
OR
digiumcertified_asteriskMatch1.8.15cert4
OR
digiumcertified_asteriskMatch11.6cert1
OR
digiumcertified_asteriskMatch11.6cert1_rc1
OR
digiumcertified_asteriskMatch11.6cert1_rc2
OR
digiumcertified_asteriskMatch11.6.0-
OR
digiumcertified_asteriskMatch11.6.0rc1
OR
digiumcertified_asteriskMatch11.6.0rc2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.599 Medium

EPSS

Percentile

97.8%