CVE Vulnerabilities

CVE-2015-1558

Published: Feb 09, 2015 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 12.0.0 (including) 12.0.0 (including)
Asterisk Digium 12.1.0 (including) 12.1.0 (including)
Asterisk Digium 12.1.0-rc1 (including) 12.1.0-rc1 (including)
Asterisk Digium 12.1.0-rc2 (including) 12.1.0-rc2 (including)
Asterisk Digium 12.1.0-rc3 (including) 12.1.0-rc3 (including)
Asterisk Digium 12.1.1 (including) 12.1.1 (including)
Asterisk Digium 12.2.0 (including) 12.2.0 (including)
Asterisk Digium 12.2.0-rc1 (including) 12.2.0-rc1 (including)
Asterisk Digium 12.2.0-rc2 (including) 12.2.0-rc2 (including)
Asterisk Digium 12.2.0-rc3 (including) 12.2.0-rc3 (including)
Asterisk Digium 12.3.0 (including) 12.3.0 (including)
Asterisk Digium 12.3.0-rc1 (including) 12.3.0-rc1 (including)
Asterisk Digium 12.3.0-rc2 (including) 12.3.0-rc2 (including)
Asterisk Digium 12.3.1 (including) 12.3.1 (including)
Asterisk Digium 12.3.2 (including) 12.3.2 (including)
Asterisk Digium 12.4.0 (including) 12.4.0 (including)
Asterisk Digium 12.4.0-rc1 (including) 12.4.0-rc1 (including)
Asterisk Digium 12.5.0 (including) 12.5.0 (including)
Asterisk Digium 12.5.0-rc1 (including) 12.5.0-rc1 (including)
Asterisk Digium 12.6.0 (including) 12.6.0 (including)
Asterisk Digium 12.6.0-rc1 (including) 12.6.0-rc1 (including)
Asterisk Digium 12.7.0 (including) 12.7.0 (including)
Asterisk Digium 12.7.0-rc1 (including) 12.7.0-rc1 (including)
Asterisk Digium 12.7.0-rc2 (including) 12.7.0-rc2 (including)
Asterisk Digium 12.8.0 (including) 12.8.0 (including)
Asterisk Digium 12.8.0-rc1 (including) 12.8.0-rc1 (including)
Asterisk Digium 12.8.0-rc2 (including) 12.8.0-rc2 (including)
Asterisk Digium 12.8.1 (including) 12.8.1 (including)
Asterisk Digium 13.0.0 (including) 13.0.0 (including)
Asterisk Digium 13.1.0 (including) 13.1.0 (including)
Asterisk Digium 13.1.0-rc1 (including) 13.1.0-rc1 (including)
Asterisk Digium 13.1.0-rc2 (including) 13.1.0-rc2 (including)
Asterisk Digium 13.2.0 (including) 13.2.0 (including)
Asterisk Digium 13.2.0-rc1 (including) 13.2.0-rc1 (including)
Asterisk Ubuntu artful *
Asterisk Ubuntu lucid *
Asterisk Ubuntu upstream *
Asterisk Ubuntu vivid *
Asterisk Ubuntu wily *
Asterisk Ubuntu yakkety *
Asterisk Ubuntu zesty *

References