CVE-2009-0871

medium

Description

The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.

References

http://www.vupen.com/english/advisories/2009/0667

http://www.securitytracker.com/id?1021834

http://www.securityfocus.com/bid/34070

http://www.securityfocus.com/archive/1/501656/100/0/threaded

http://secunia.com/advisories/34229

http://osvdb.org/52568

http://downloads.digium.com/pub/security/AST-2009-002.html

http://bugs.digium.com/view.php?id=14417

http://bugs.digium.com/view.php?id=13547

Details

Source: Mitre, NVD

Published: 2009-03-11

Updated: 2018-10-10

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium