CVE-2012-3812: Double Free
Double free vulnerability in apps/appvoicemail.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digiumphones allows remote authenticated users to cause a denial of service (daemon crash) by establishing multiple voicemail sessions and accessing both the Urgent mailbox and the INBOX mailbox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3812?
The severity of CVE-2012-3812 is classified as high due to its potential to cause denial of service.
How do I fix CVE-2012-3812?
To fix CVE-2012-3812, upgrade Asterisk to version 1.8.13.1 or 10.5.2 or later.
What systems are affected by CVE-2012-3812?
CVE-2012-3812 affects Asterisk versions 1.8.x prior to 1.8.13.1 and 10.x prior to 10.5.2.
Is CVE-2012-3812 remotely exploitable?
Yes, CVE-2012-3812 can be exploited by remote authenticated users.
What impact does CVE-2012-3812 have on Asterisk?
CVE-2012-3812 allows remote authenticated users to cause a denial of service in Asterisk.