CVE-2014-2287: Input Validation
channels/chansip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chansip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2287?
CVE-2014-2287 has a medium severity rating as it allows remote authenticated users to cause a denial of service.
How do I fix CVE-2014-2287?
To fix CVE-2014-2287, upgrade Asterisk to the latest version where this vulnerability is patched, specifically versions 1.8.26.1, 11.8.1, 12.1.1, and corresponding certified Asterisk versions.
Who is affected by CVE-2014-2287?
CVE-2014-2287 affects Asterisk Open Source and Certified Asterisk versions earlier than the specified patched versions.
What type of vulnerability is CVE-2014-2287?
CVE-2014-2287 is classified as a denial of service vulnerability.
Can CVE-2014-2287 be exploited remotely?
Yes, CVE-2014-2287 can be exploited by remote authenticated users.