The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.
2014-11-26T15:59:01.447
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | digium | asterisk | 12.0.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |
Application | digium | asterisk | 12.1.0 | Yes |
Application | digium | asterisk | 12.2.0 | Yes |
Application | digium | asterisk | 12.2.0 | Yes |
Application | digium | asterisk | 12.2.0 | Yes |
Application | digium | asterisk | 12.2.0 | Yes |
Application | digium | asterisk | 12.3.0 | Yes |
Application | digium | asterisk | 12.3.0 | Yes |
Application | digium | asterisk | 12.3.0 | Yes |
Application | digium | asterisk | 12.4.0 | Yes |
Application | digium | asterisk | 12.4.0 | Yes |
Application | digium | asterisk | 12.5.0 | Yes |
Application | digium | asterisk | 12.5.0 | Yes |