res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers, which triggers an invalid pointer dereference.
2014-04-18T22:14:38.137
2025-04-12T10:46:40.837
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:N/A:P
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | digium | asterisk | 12.0.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |