Unrated severityNVD Advisory· Published Mar 11, 2009· Updated Apr 23, 2026
CVE-2009-0871
CVE-2009-0871
Description
The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.
Affected products
30cpe:2.3:a:digium:asterisk:1.4.22:*:*:*:*:*:*:*+ 29 more
- cpe:2.3:a:digium:asterisk:1.4.22:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.4.23:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.4.23.1:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0.3:rc1:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0.4:rc1:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta7.1:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:beta9:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:rc5:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.0:rc6:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.1:beta1:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.1:beta2:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.1:beta3:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.1:beta4:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:1.6.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:digium:asterisk:c.2.3:-:business:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- downloads.digium.com/pub/security/AST-2009-002.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/34070nvdPatch
- secunia.com/advisories/34229nvdVendor Advisory
- bugs.digium.com/view.phpnvd
- bugs.digium.com/view.phpnvd
- osvdb.org/52568nvd
- www.securityfocus.com/archive/1/501656/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2009/0667nvd
News mentions
0No linked articles in our index yet.