CVE-2014-4047Asterisk vulnerability

7 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
3.0%
top 13.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 14

Description

Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDdigium/certified_asterisk1.8.15, 11.6, 11.6.0+2
debiandebian/asterisk< asterisk 1:11.10.2~dfsg-1 (bullseye)
Debiandigium/asterisk< 1:11.10.2~dfsg-1
NVDdigium/asterisk84 versions+83

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g85f-5xc2-36cg: Asterisk Open Source 12022-05-14
OSV
CVE-2014-4047: Asterisk Open Source 12014-06-17

📋Vendor Advisories

1
Debian
CVE-2014-4047: asterisk - Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before...2014

💬Community

3
Bugzilla
CVE-2014-4047 asterisk: DoS due to Exhaustion of Allowed Concurrent HTTP Connections (AST-2014-007)2014-06-13
Bugzilla
CVE-2014-4047 asterisk: DoS due to Exhaustion of Allowed Concurrent HTTP Connections (AST-2014-007) [epel-6]2014-06-13
Bugzilla
CVE-2014-4047 asterisk: DoS due to Exhaustion of Allowed Concurrent HTTP Connections (AST-2014-007) [fedora-all]2014-06-13
CVE-2014-4047 — Debian Asterisk vulnerability | cvebase