CVE-2014-4047: Medium severity Digium Asterisk Appliance Developer Kit vulnerability
Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4047?
CVE-2014-4047 is classified as a denial of service vulnerability that allows remote attackers to significantly consume connection resources.
How do I fix CVE-2014-4047?
To fix CVE-2014-4047, upgrade Asterisk to versions 1.8.28.1, 11.10.1, or 12.3.1 or later.
Which Asterisk versions are affected by CVE-2014-4047?
CVE-2014-4047 affects Asterisk Open Source versions 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1.
Can CVE-2014-4047 lead to a service outage?
Yes, CVE-2014-4047 can lead to service outages by overwhelming Asterisk with a large number of inactive or incomplete HTTP connections.
Is CVE-2014-4047 easy to exploit?
CVE-2014-4047 can be easily exploited by remote attackers who can send a large number of HTTP requests to the vulnerable server.