// For flags

CVE-2008-2119

Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.

Asterisk Open Source 1.0.x y 1.2.x anterior 1.2.29 y Business Edition A.x.x y B.x.x anterior B.2.5.3, cuando "pedantic parsing" (también conocido como pedanticsipchecking) está activado, permite a atacantes remotos provocar una denegación de servicio (caída de demonio) a través de un mensaje SIP INVITE que carece de una cabecera From, relacionado con la invocación de la función ast_uri_decode y el manejo incorrecto de (1) una cadena const vacía y (2) un puntero NULL.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-05-08 CVE Reserved
  • 2008-06-04 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-04-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
<= b2.5.2
Search vendor "Asterisk" for product "Asterisk Business Edition" and version " <= b2.5.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.1.3.2
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.1.3.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.1.3.3
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.1.3.3"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.2.0
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.2.0"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.2.1
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.2.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.1
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.2
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.3
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.3"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.4
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.4"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.5.0
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.5.0"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b2.5.1
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b2.5.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
<= 1.2.28
Search vendor "Asterisk" for product "Open Source" and version " <= 1.2.28"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0
Search vendor "Asterisk" for product "Open Source" and version "1.0"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.0
Search vendor "Asterisk" for product "Open Source" and version "1.0.0"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.1
Search vendor "Asterisk" for product "Open Source" and version "1.0.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.2
Search vendor "Asterisk" for product "Open Source" and version "1.0.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.3
Search vendor "Asterisk" for product "Open Source" and version "1.0.3"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.4
Search vendor "Asterisk" for product "Open Source" and version "1.0.4"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.5
Search vendor "Asterisk" for product "Open Source" and version "1.0.5"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.6
Search vendor "Asterisk" for product "Open Source" and version "1.0.6"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.7
Search vendor "Asterisk" for product "Open Source" and version "1.0.7"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.8
Search vendor "Asterisk" for product "Open Source" and version "1.0.8"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.9
Search vendor "Asterisk" for product "Open Source" and version "1.0.9"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.11
Search vendor "Asterisk" for product "Open Source" and version "1.0.11"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.11.1
Search vendor "Asterisk" for product "Open Source" and version "1.0.11.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.0.12
Search vendor "Asterisk" for product "Open Source" and version "1.0.12"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.0
Search vendor "Asterisk" for product "Open Source" and version "1.2.0"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.0beta1
Search vendor "Asterisk" for product "Open Source" and version "1.2.0beta1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.0beta2
Search vendor "Asterisk" for product "Open Source" and version "1.2.0beta2"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.1
Search vendor "Asterisk" for product "Open Source" and version "1.2.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.2
Search vendor "Asterisk" for product "Open Source" and version "1.2.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.10
Search vendor "Asterisk" for product "Open Source" and version "1.2.10"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.11
Search vendor "Asterisk" for product "Open Source" and version "1.2.11"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.12
Search vendor "Asterisk" for product "Open Source" and version "1.2.12"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.12.1
Search vendor "Asterisk" for product "Open Source" and version "1.2.12.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.13
Search vendor "Asterisk" for product "Open Source" and version "1.2.13"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.14
Search vendor "Asterisk" for product "Open Source" and version "1.2.14"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.15
Search vendor "Asterisk" for product "Open Source" and version "1.2.15"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.16
Search vendor "Asterisk" for product "Open Source" and version "1.2.16"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.17
Search vendor "Asterisk" for product "Open Source" and version "1.2.17"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.18
Search vendor "Asterisk" for product "Open Source" and version "1.2.18"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.19
Search vendor "Asterisk" for product "Open Source" and version "1.2.19"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.20
Search vendor "Asterisk" for product "Open Source" and version "1.2.20"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.21
Search vendor "Asterisk" for product "Open Source" and version "1.2.21"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.21.1
Search vendor "Asterisk" for product "Open Source" and version "1.2.21.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.22
Search vendor "Asterisk" for product "Open Source" and version "1.2.22"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.23
Search vendor "Asterisk" for product "Open Source" and version "1.2.23"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.24
Search vendor "Asterisk" for product "Open Source" and version "1.2.24"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.25
Search vendor "Asterisk" for product "Open Source" and version "1.2.25"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.26
Search vendor "Asterisk" for product "Open Source" and version "1.2.26"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.26.1
Search vendor "Asterisk" for product "Open Source" and version "1.2.26.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.26.2
Search vendor "Asterisk" for product "Open Source" and version "1.2.26.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.27
Search vendor "Asterisk" for product "Open Source" and version "1.2.27"
-
Affected