CVE-2014-2286: Input Validation
main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2286?
CVE-2014-2286 has a severity rating that classifies it as a significant risk due to its potential for denial of service and possible arbitrary code execution.
How do I fix CVE-2014-2286?
To fix CVE-2014-2286, upgrade Asterisk to versions 1.8.26.1 or later, 11.8.1 or later, or 12.1.1 or later.
What types of systems are affected by CVE-2014-2286?
CVE-2014-2286 affects various versions of Asterisk Open Source and Certified Asterisk systems prior to specified updates.
What could an attacker potentially exploit in CVE-2014-2286?
An attacker could exploit CVE-2014-2286 to cause a denial of service through stack consumption and potentially execute arbitrary code.
Is there an exploit available for CVE-2014-2286?
Though specific exploit code for CVE-2014-2286 may not be publicly detailed, the vulnerability allows remote attackers to impact system performance and security.