VYPR
Unrated severityNVD Advisory· Published Apr 18, 2014· Updated Jun 17, 2026

CVE-2014-2289

CVE-2014-2289

Description

res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers, which triggers an invalid pointer dereference.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Digium/Asterisk4 versions
    cpe:2.3:a:digium:asterisk:12.0.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:digium:asterisk:12.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:12.1.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:12.1.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:digium:asterisk:12.1.0:rc3:*:*:*:*:*:*
  • Range: <12.1.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.