CVE-2014-6610

MEDIUM

Description

Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.

References

http://downloads.asterisk.org/pub/security/AST-2014-010.html

Details

Source: MITRE

Published: 2014-11-26

Updated: 2014-11-26

Type: CWE-19

Risk Information

CVSS v2.0

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:digium:certified_asterisk:11.6:cert1:*:*:lts:*:*:*

cpe:2.3:a:digium:certified_asterisk:11.6:cert2:*:*:lts:*:*:*

cpe:2.3:a:digium:certified_asterisk:11.6:cert3:*:*:lts:*:*:*

cpe:2.3:a:digium:certified_asterisk:11.6:cert4:*:*:lts:*:*:*

cpe:2.3:a:digium:certified_asterisk:11.6:cert5:*:*:lts:*:*:*

cpe:2.3:a:digium:certified_asterisk:11.6.0:*:*:*:lts:*:*:*

Configuration 2

OR

cpe:2.3:a:digium:asterisk:11.0.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.0.0:beta1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.0.0:beta2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.0.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.0.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.1.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.1.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.1.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.1.0:rc3:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.2.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.2.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.2.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.3.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.3.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.4.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.4.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.4.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.4.0:rc3:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.4.0:rc4:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.5.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.5.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.5.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.6.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.6.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.6.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.7.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.7.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.7.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.8.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.8.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.8.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.8.0:rc3:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.9.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.9.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.9.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.9.0:rc3:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.10.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.10.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.11.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.11.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:11.12.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.0.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.1.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.1.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.1.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.1.0:rc3:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.2.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.2.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.2.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.2.0:rc3:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.3.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.3.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.3.0:rc2:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.4.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.4.0:rc1:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.5.0:*:*:*:*:*:*:*

cpe:2.3:a:digium:asterisk:12.5.0:rc1:*:*:*:*:*:*

Tenable Plugins

View all (4 total)

IDNameProductFamilySeverity
90873Debian DLA-455-1 : asterisk security updateNessusDebian Local Security Checks
high
79418GLSA-201411-10 : Asterisk: Multiple Vulnerabilities (POODLE)NessusGentoo Local Security Checks
medium
79405Mandriva Linux Security Advisory : asterisk (MDVSA-2014:218)NessusMandriva Local Security Checks
medium
77859Asterisk ReceiveFax Dialplan Application Remote DoS (AST-2014-010)NessusMisc.
medium