The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.
2008-01-08T02:46:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | asterisk | asterisk_appliance_developer_kit | ≤ 1.4_revision_95945 | Yes |
Application | asterisk | asterisk_business_edition | ≤ c.1.0beta7 | Yes |
Application | asterisk | asterisknow | ≤ beta_6 | Yes |
Application | asterisk | open_source | ≤ 1.4.16 | Yes |
Application | asterisk | s800i | ≤ 1.0.3.3 | Yes |