CVE-2014-9374: Double Free
Double free vulnerability in the WebSocket Server (reshttpwebsocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9374?
CVE-2014-9374 has a high severity as it can lead to denial of service attacks through a double free vulnerability.
How do I fix CVE-2014-9374?
To fix CVE-2014-9374, update Asterisk to versions 11.14.2, 12.7.2, 13.0.2, or later.
Which versions of Asterisk are affected by CVE-2014-9374?
Asterisk versions 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 are affected by CVE-2014-9374.
What causes the vulnerability CVE-2014-9374?
CVE-2014-9374 is caused by a double free vulnerability in the WebSocket Server module of Asterisk.
Can CVE-2014-9374 be exploited remotely?
Yes, attackers can exploit CVE-2014-9374 remotely by sending a zero-length frame to the WebSocket Server.