Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-4598
HistoryDec 15, 2011 - 12:00 a.m.

CVE-2011-4598

2011-12-1500:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.042

Percentile

92.3%

The handle_request_info function in channels/chan_sip.c in Asterisk Open
Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is
enabled, allows remote attackers to cause a denial of service (NULL pointer
dereference and daemon crash) via a crafted sequence of SIP requests.

Bugs

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.042

Percentile

92.3%