FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-5642

This CVE name corresponds to:

Entered Topic
2013-08-28 asterisk -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-5642
Phase Assigned(20130828)

Description

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.3-digiumphones allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and daemon crash) via an invalid SDP that defines a media description before the connection description in a SIP request.

References

Source Reference
BUGTRAQ 20130827 AST-2013-005: Remote Crash when Invalid SDP is sent in SIP Request
CONFIRM http://downloads.asterisk.org/pub/security/AST-2013-005.html
CONFIRM https://issues.asterisk.org/jira/browse/ASTERISK-22007
DEBIAN DSA-2749
MANDRIVA MDVSA-2013:223
BID 62022
OSVDB 96690
SECTRACK 1028957
SECUNIA 54534
SECUNIA 54617