CVE-2011-2216 — Asterisk vulnerability
8 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
3.5%
top 12.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 6
Latest updateMay 14
Description
reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed Contact header.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2💥Exploits & PoCs
1📋Vendor Advisories
1Debian▶
CVE-2011-2216: asterisk - reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before ...↗2011
💬Community
3Bugzilla
▶
Bugzilla▶
CVE-2011-2216 Asterisk: Remote DoS (crash) in SIP channel driver (AST-2011-007) [fedora-15]↗2011-06-03