CVE-2008-2119: Input Validation
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the asturidecode function, and improper handling of (1) an empty const string and (2) a NULL pointer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2119?
CVE-2008-2119 is classified as a denial of service vulnerability that can cause the Asterisk daemon to crash.
How do I fix CVE-2008-2119?
To fix CVE-2008-2119, upgrade Asterisk to version 1.2.29 or later, or to version B.2.5.3 or later for Business Edition.
Which versions are affected by CVE-2008-2119?
CVE-2008-2119 affects Asterisk Open Source versions 1.0.x and 1.2.x before 1.2.29, as well as Business Edition versions A.x.x and B.x.x before B.2.5.3.
What causes the vulnerability CVE-2008-2119?
CVE-2008-2119 is caused by a SIP INVITE message that lacks a From header when pedantic parsing is enabled, leading to a crash.
Who is impacted by CVE-2008-2119?
Users of Asterisk Open Source and Business Edition versions specified in CVE-2008-2119 are at risk of service interruption due to this vulnerability.