Lucene search

K
cve[email protected]CVE-2014-9374
HistoryDec 12, 2014 - 3:59 p.m.

CVE-2014-9374

2014-12-1215:59:14
web.nvd.nist.gov
34
cve-2014-9374
websocket server
asterisk open source
vulnerability
denial of service
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.6%

Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame.

Affected configurations

NVD
Node
digiumcertified_asteriskMatch11.6cert1lts
OR
digiumcertified_asteriskMatch11.6cert2lts
OR
digiumcertified_asteriskMatch11.6cert3lts
OR
digiumcertified_asteriskMatch11.6cert4lts
OR
digiumcertified_asteriskMatch11.6cert5lts
OR
digiumcertified_asteriskMatch11.6cert6lts
OR
digiumcertified_asteriskMatch11.6cert7lts
OR
digiumcertified_asteriskMatch11.6cert8lts
OR
digiumcertified_asteriskMatch11.6.0lts
Node
digiumasteriskMatch11.0.0
OR
digiumasteriskMatch11.0.0beta1
OR
digiumasteriskMatch11.0.0beta2
OR
digiumasteriskMatch11.0.0rc1
OR
digiumasteriskMatch11.0.0rc2
OR
digiumasteriskMatch11.1.0
OR
digiumasteriskMatch11.1.0rc1
OR
digiumasteriskMatch11.1.0rc2
OR
digiumasteriskMatch11.1.0rc3
OR
digiumasteriskMatch11.2.0
OR
digiumasteriskMatch11.2.0rc1
OR
digiumasteriskMatch11.2.0rc2
OR
digiumasteriskMatch11.3.0rc1
OR
digiumasteriskMatch11.3.0rc2
OR
digiumasteriskMatch11.4.0
OR
digiumasteriskMatch11.4.0rc1
OR
digiumasteriskMatch11.4.0rc2
OR
digiumasteriskMatch11.4.0rc3
OR
digiumasteriskMatch11.4.0rc4
OR
digiumasteriskMatch11.5.0
OR
digiumasteriskMatch11.5.0rc1
OR
digiumasteriskMatch11.5.0rc2
OR
digiumasteriskMatch11.6.0
OR
digiumasteriskMatch11.6.0rc1
OR
digiumasteriskMatch11.6.0rc2
OR
digiumasteriskMatch11.7.0
OR
digiumasteriskMatch11.7.0rc1
OR
digiumasteriskMatch11.7.0rc2
OR
digiumasteriskMatch11.8.0
OR
digiumasteriskMatch11.8.0rc1
OR
digiumasteriskMatch11.8.0rc2
OR
digiumasteriskMatch11.8.0rc3
OR
digiumasteriskMatch11.9.0
OR
digiumasteriskMatch11.9.0rc1
OR
digiumasteriskMatch11.9.0rc2
OR
digiumasteriskMatch11.9.0rc3
OR
digiumasteriskMatch11.10.0
OR
digiumasteriskMatch11.10.0rc1
OR
digiumasteriskMatch11.11.0
OR
digiumasteriskMatch11.11.0rc1
OR
digiumasteriskMatch11.12.0
OR
digiumasteriskMatch11.12.0rc1
OR
digiumasteriskMatch11.13.0
OR
digiumasteriskMatch11.13.0rc1
OR
digiumasteriskMatch11.14.0
OR
digiumasteriskMatch11.14.0rc1
OR
digiumasteriskMatch11.14.0rc2
OR
digiumasteriskMatch12.0.0
OR
digiumasteriskMatch12.1.0
OR
digiumasteriskMatch12.1.0rc1
OR
digiumasteriskMatch12.1.0rc2
OR
digiumasteriskMatch12.1.0rc3
OR
digiumasteriskMatch12.2.0
OR
digiumasteriskMatch12.2.0rc1
OR
digiumasteriskMatch12.2.0rc2
OR
digiumasteriskMatch12.2.0rc3
OR
digiumasteriskMatch12.3.0
OR
digiumasteriskMatch12.3.0rc1
OR
digiumasteriskMatch12.3.0rc2
OR
digiumasteriskMatch12.4.0
OR
digiumasteriskMatch12.4.0rc1
OR
digiumasteriskMatch12.5.0
OR
digiumasteriskMatch12.5.0rc1
OR
digiumasteriskMatch12.6.0
OR
digiumasteriskMatch12.6.0rc1
OR
digiumasteriskMatch12.7.0
OR
digiumasteriskMatch12.7.0rc1
OR
digiumasteriskMatch12.7.0rc2
OR
digiumasteriskMatch12.7.1
OR
digiumasteriskMatch13.0.0
OR
digiumasteriskMatch13.0.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.6%