CVE-2006-5445: High severity Asterisk vulnerability
Unspecified vulnerability in the SIP channel driver (channels/chansip.c) in Asterisk 1.2.x before 1.2.13 and 1.4.x before 1.4.0-beta3 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors that result in the creation of "a real pvt structure" that uses more resources than necessary.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5445?
CVE-2006-5445 has been classified as having a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2006-5445?
To fix CVE-2006-5445, you should upgrade to Asterisk version 1.2.13 or later, or 1.4.0-beta3 or later.
Which Asterisk versions are affected by CVE-2006-5445?
CVE-2006-5445 affects Asterisk versions 1.2.x before 1.2.13 and 1.4.x before 1.4.0-beta3.
What type of vulnerability is CVE-2006-5445?
CVE-2006-5445 is a denial of service vulnerability that can lead to resource consumption.
Can CVE-2006-5445 be exploited remotely?
Yes, CVE-2006-5445 can be exploited by remote attackers without requiring local access.