Get a Pentest and security assessment of your IT network.

2021-current

CVE-2015-1558 – Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when usin

Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1558

Reference (s):

  • BUGTRAQ:20150128 AST-2015-001: File descriptor leak when incompatible codecs are offered
  • URL: http://www.securityfocus.com/archive/1/534573/100/0/threaded
  • http://downloads.asterisk.org/pub/security/AST-2015-001.html
  • FULLDISC:20150128 AST-2015-001: File descriptor leak when incompatible codecs are offered
  • URL: http://seclists.org/fulldisclosure/2015/Jan/116
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9236 - Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (

2021-current

CVE-2020-0829 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14828 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser