CVE-2012-2948: Null Pointer Dereference
chanskinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by closing a connection in off-hook mode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2948?
CVE-2012-2948 is classified as a medium severity vulnerability that can lead to a denial of service due to a NULL pointer dereference.
How do I fix CVE-2012-2948?
To fix CVE-2012-2948, upgrade to Certified Asterisk 1.8.11-cert2 or later, or Asterisk Open Source 1.8.12.1 or later.
What software versions are affected by CVE-2012-2948?
CVE-2012-2948 affects Certified Asterisk 1.8.11-cert before 1.8.11-cert2, Asterisk Open Source 1.8.x before 1.8.12.1, and 10.x before 10.4.1.
What type of attack does CVE-2012-2948 enable?
CVE-2012-2948 enables remote authenticated users to perform a denial of service attack by causing the daemon to crash.
Is there any workaround for CVE-2012-2948?
There are no known workarounds for CVE-2012-2948; patching or upgrading is recommended.