The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Asterisk | 1.2.14 (including) | 1.2.14 (including) |
Asterisk | Asterisk | 1.2.15 (including) | 1.2.15 (including) |
Asterisk | Asterisk | 1.2.16 (including) | 1.2.16 (including) |
Asterisk | Asterisk | 1.4.1 (including) | 1.4.1 (including) |
Asterisk | Ubuntu | dapper | * |
Asterisk | Ubuntu | devel | * |
Asterisk | Ubuntu | edgy | * |
Asterisk | Ubuntu | feisty | * |
Asterisk | Ubuntu | gutsy | * |
Asterisk | Ubuntu | upstream | * |