← Back

CVE-2014-6610

nvd nist
Published: Nov 26, 2014Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:N/A:P
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.

Affected (63)

2 products
Certified Asterisk
Asterisk
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 11.6.0
Version 11.6 cert1
Version 11.6 cert2
Version 11.6 cert3
Version 11.6 cert4
Version 11.6 cert5
Configuration B
57 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 11.0.0
Version 11.0.0 beta1
Version 11.0.0 beta2
Version 11.0.0 rc1
Version 11.0.0 rc2
Version 11.1.0
Version 11.1.0 rc1
Version 11.1.0 rc2
Version 11.1.0 rc3
Version 11.10.0
Version 11.10.0 rc1
Version 11.11.0
Version 11.11.0 rc1
Version 11.12.0
Version 11.2.0
Version 11.2.0 rc1
Version 11.2.0 rc2
Version 11.3.0 rc1
Version 11.3.0 rc2
Version 11.4.0
Version 11.4.0 rc1
Version 11.4.0 rc2
Version 11.4.0 rc3
Version 11.4.0 rc4
Version 11.5.0
Version 11.5.0 rc1
Version 11.5.0 rc2
Version 11.6.0
Version 11.6.0 rc1
Version 11.6.0 rc2
Version 11.7.0
Version 11.7.0 rc1
Version 11.7.0 rc2
Version 11.8.0
Version 11.8.0 rc1
Version 11.8.0 rc2
Version 11.8.0 rc3
Version 11.9.0
Version 11.9.0 rc1
Version 11.9.0 rc2
Version 11.9.0 rc3
Version 12.0.0
Version 12.1.0
Version 12.1.0 rc1
Version 12.1.0 rc2
Version 12.1.0 rc3
Version 12.2.0
Version 12.2.0 rc1
Version 12.2.0 rc2
Version 12.2.0 rc3
Version 12.3.0
Version 12.3.0 rc1
Version 12.3.0 rc2
Version 12.4.0
Version 12.4.0 rc1
Version 12.5.0
Version 12.5.0 rc1

Related CWEs

References (2)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.