CVE-2015-1558
published 2015-02-09CVE-2015-1558: Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote…
PriorityP417low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
3.03%
85.8th percentile
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | asterisk | < asterisk 1:13.1.0~dfsg-1.1 (bullseye) | asterisk 1:13.1.0~dfsg-1.1 (bullseye) |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | — | — |
| digium | asterisk | >= 0 < 1:13.1.0~dfsg-1.1 | 1:13.1.0~dfsg-1.1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-1558: asterisk - Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the P...
vendor_debian·2015·CVSS 3.5
CVE-2015-1558 [LOW] CVE-2015-1558: asterisk - Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the P...
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
Scope: local
bullseye: resolved (fixed in 1:13.1.0~dfsg-1.1)
sid: resolved (fixed in 1:13.1.0~dfsg-1.1)
GHSA
GHSA-c6qp-2qc4-4h58: Asterisk Open Source 12
ghsa_unreviewed·2022-05-14
CVE-2015-1558 [LOW] GHSA-c6qp-2qc4-4h58: Asterisk Open Source 12
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
OSV
CVE-2015-1558: Asterisk Open Source 12
osv·2015-02-09·CVSS 3.5
CVE-2015-1558 [LOW] CVE-2015-1558: Asterisk Open Source 12
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
No detection rules found.
No public exploits indexed.
http://downloads.asterisk.org/pub/security/AST-2015-001.htmlhttp://seclists.org/fulldisclosure/2015/Jan/116http://www.securityfocus.com/archive/1/534573/100/0/threadedhttp://www.securitytracker.com/id/1031661http://downloads.asterisk.org/pub/security/AST-2015-001.htmlhttp://seclists.org/fulldisclosure/2015/Jan/116http://www.securityfocus.com/archive/1/534573/100/0/threadedhttp://www.securitytracker.com/id/1031661
2015-02-09
Published