CVE-2009-0871

The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:digium:asterisk:1.4.22:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.4.23:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.4.23.1:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta4:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta5:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta6:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta7:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta7.1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta8:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:beta9:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:rc4:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:rc5:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0:rc6:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0.3:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0.4:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.0.5:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.1:beta1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.1:beta2:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.1:beta3:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.1:beta4:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:1.6.1:rc1:*:*:*:*:*:*
cpe:2.3:a:digium:asterisk:c.2.3:-:business:*:*:*:*:*

History

No history.

Information

Published : 2009-03-11 14:19

Updated : 2024-02-04 17:33


NVD link : CVE-2009-0871

Mitre link : CVE-2009-0871

CVE.ORG link : CVE-2009-0871


JSON object : View

Products Affected

digium

  • asterisk
CWE
CWE-20

Improper Input Validation