CVE-2014-8415
Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a cancel request for a SIP session with a queued…
Does this matter?
Lower severity and a low EPSS score (3.04%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a cancel request for a SIP session with a queued action to (1) answer a session or (2) send ringing.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.04% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- digium/asterisk
- Source
- cve@mitre.org
References
- http://downloads.asterisk.org/pub/security/AST-2014-015.htmlVendor Advisory
- http://downloads.asterisk.org/pub/security/AST-2014-015.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.