Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-0095


The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.


Published

2008-01-08T02:46:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application asterisk asterisk_appliance_developer_kit ≤ 1.4_revision_95945 Yes
Application asterisk asterisk_business_edition ≤ c.1.0beta7 Yes
Application asterisk asterisknow ≤ beta_6 Yes
Application asterisk open_source ≤ 1.4.16 Yes
Application asterisk s800i ≤ 1.0.3.3 Yes

References