CVE Vulnerabilities

CVE-2008-0095

Published: Jan 08, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.

Affected Software

NameVendorStart VersionEnd Version
Asterisk_appliance_developer_kitAsterisk*1.4_revision_95945 (including)
Asterisk_business_editionAsterisk*c.1.0beta7 (including)
AsterisknowAsterisk*beta_6 (including)
Open_sourceAsterisk*1.4.16 (including)
S800iAsterisk*1.0.3.3 (including)
AsteriskUbuntudevel*
AsteriskUbuntugutsy*
AsteriskUbuntuhardy*
AsteriskUbuntuintrepid*
AsteriskUbuntuupstream*

References