Vulnerability CVE-2014-6610


Published: 2014-11-26

Description:
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.

Type:

CWE-19

(Data Handling)

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Digium -> Asterisk 
Digium -> Certified asterisk 

 References:
http://downloads.asterisk.org/pub/security/AST-2014-010.html

Copyright 2024, cxsecurity.com

 

Back to Top