CVE-2012-3553: Null Pointer Dereference
chanskinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and closing a connection in off-hook mode, a related issue to CVE-2012-2948.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3553?
CVE-2012-3553 is classified as a high severity vulnerability due to its potential to create a denial of service situation.
How do I fix CVE-2012-3553?
To fix CVE-2012-3553, upgrade Asterisk to version 10.5.1 or later.
Who is affected by CVE-2012-3553?
CVE-2012-3553 affects authenticated users of Asterisk versions 10.x prior to 10.5.1.
What type of attack does CVE-2012-3553 enable?
CVE-2012-3553 enables a denial of service attack by causing a NULL pointer dereference and crashing the daemon.
Is CVE-2012-3553 an authentication issue?
No, CVE-2012-3553 requires that users be authenticated to exploit the vulnerability.