CVE-2015-1558: Low severity asterisk vulnerability
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1558?
CVE-2015-1558 has a severity rating that indicates a potential denial of service risk affecting Asterisk installations.
How do I fix CVE-2015-1558?
To fix CVE-2015-1558, upgrade Asterisk to version 12.8.1 or 13.1.1 or later.
What is the impact of CVE-2015-1558?
The impact of CVE-2015-1558 is file descriptor consumption leading to a denial of service for remote authenticated users.
Which versions of Asterisk are affected by CVE-2015-1558?
CVE-2015-1558 affects Asterisk versions 12.x before 12.8.1 and 13.x before 13.1.1.
Is remote authentication required to exploit CVE-2015-1558?
Yes, CVE-2015-1558 can only be exploited by remote authenticated users.