Vulnerability Description
chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and closing a connection in off-hook mode, a related issue to CVE-2012-2948.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | 10.0.0 |
References
- http://downloads.asterisk.org/pub/security/AST-2012-009.htmlVendor Advisory
- http://downloads.asterisk.org/pub/security/AST-2012-009.htmlVendor Advisory
FAQ
What is CVE-2012-3553?
CVE-2012-3553 is a vulnerability with a CVSS score of 4.0 (MEDIUM). chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon cra...
How severe is CVE-2012-3553?
CVE-2012-3553 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-3553?
Check the references section above for vendor advisories and patch information. Affected products include: Digium Asterisk.