CVE-2015-1558
 
Severity Score
3.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
Asterisk Open Source 12.x anterior a 12.8.1 y 13.x anterior a 13.1.1, cuando utiliza el controlador de canales PJSIP, no recupera correctamente los puertos RTP, lo que permite a usuarios remotos autenticados causar una denegación de servicio (consumo del descriptor de ficheros) a través de una oferta SDP que contiene solamente codecs incompatibles.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-02-08 CVE Reserved
- 2015-02-09 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2015/Jan/116 | Mailing List | |
http://www.securityfocus.com/archive/1/534573/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id/1031661 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://downloads.asterisk.org/pub/security/AST-2015-001.html | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.0.0 Search vendor "Digium" for product "Asterisk" and version "12.0.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.1.0 Search vendor "Digium" for product "Asterisk" and version "12.1.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.1.0 Search vendor "Digium" for product "Asterisk" and version "12.1.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.1.0 Search vendor "Digium" for product "Asterisk" and version "12.1.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.1.0 Search vendor "Digium" for product "Asterisk" and version "12.1.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.1.1 Search vendor "Digium" for product "Asterisk" and version "12.1.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.2.0 Search vendor "Digium" for product "Asterisk" and version "12.2.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.2.0 Search vendor "Digium" for product "Asterisk" and version "12.2.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.2.0 Search vendor "Digium" for product "Asterisk" and version "12.2.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.2.0 Search vendor "Digium" for product "Asterisk" and version "12.2.0" | rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.3.0 Search vendor "Digium" for product "Asterisk" and version "12.3.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.3.0 Search vendor "Digium" for product "Asterisk" and version "12.3.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.3.0 Search vendor "Digium" for product "Asterisk" and version "12.3.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.3.1 Search vendor "Digium" for product "Asterisk" and version "12.3.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.3.2 Search vendor "Digium" for product "Asterisk" and version "12.3.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.4.0 Search vendor "Digium" for product "Asterisk" and version "12.4.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.4.0 Search vendor "Digium" for product "Asterisk" and version "12.4.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.5.0 Search vendor "Digium" for product "Asterisk" and version "12.5.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.5.0 Search vendor "Digium" for product "Asterisk" and version "12.5.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.6.0 Search vendor "Digium" for product "Asterisk" and version "12.6.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.6.0 Search vendor "Digium" for product "Asterisk" and version "12.6.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.7.0 Search vendor "Digium" for product "Asterisk" and version "12.7.0" | lts |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.7.0 Search vendor "Digium" for product "Asterisk" and version "12.7.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.7.0 Search vendor "Digium" for product "Asterisk" and version "12.7.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.8.0 Search vendor "Digium" for product "Asterisk" and version "12.8.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.8.0 Search vendor "Digium" for product "Asterisk" and version "12.8.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.8.0 Search vendor "Digium" for product "Asterisk" and version "12.8.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 12.8.1 Search vendor "Digium" for product "Asterisk" and version "12.8.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 13.0.0 Search vendor "Digium" for product "Asterisk" and version "13.0.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 13.1.0 Search vendor "Digium" for product "Asterisk" and version "13.1.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 13.1.0 Search vendor "Digium" for product "Asterisk" and version "13.1.0" | rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 13.1.0 Search vendor "Digium" for product "Asterisk" and version "13.1.0" | rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 13.2.0 Search vendor "Digium" for product "Asterisk" and version "13.2.0" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 13.2.0 Search vendor "Digium" for product "Asterisk" and version "13.2.0" | rc1 |
Affected
|