MEDIUM · 4.3

CVE-2014-4048

The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (deadlock) by terminating a subscription request before it is complete, which trigge...

Vulnerability Description

The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (deadlock) by terminating a subscription request before it is complete, which triggers a SIP transaction timeout.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
DigiumAsterisk<= 12.3.0

References

FAQ

What is CVE-2014-4048?

CVE-2014-4048 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (deadlock) by terminating a subscription request before it is complete, which trigge...

How severe is CVE-2014-4048?

CVE-2014-4048 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-4048?

Check the references section above for vendor advisories and patch information. Affected products include: Digium Asterisk.