CVE-2008-2119 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)
Patch early
A public exploit exists.
Description
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
| EPSS | 7.27% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-06-04 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| asterisk | asterisk business edition |
| asterisk | open source |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash | 2008-06-05 |
References
- http://bugs.digium.com/view.php?id=12607
- http://downloads.digium.com/pub/security/AST-2008-008.html
- http://secunia.com/advisories/30517
- http://secunia.com/advisories/34982
- http://security.gentoo.org/glsa/glsa-200905-01.xml
- http://svn.digium.com/view/asterisk?view=rev&revision=120109
- http://www.securityfocus.com/archive/1/493020/100/0/threaded
- http://www.securitytracker.com/id?1020166
- http://www.vupen.com/english/advisories/2008/1731
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42823
- https://www.exploit-db.com/exploits/5749
- http://bugs.digium.com/view.php?id=12607
- http://downloads.digium.com/pub/security/AST-2008-008.html
- http://secunia.com/advisories/30517
- http://secunia.com/advisories/34982
- http://security.gentoo.org/glsa/glsa-200905-01.xml
- http://svn.digium.com/view/asterisk?view=rev&revision=120109
- http://www.securityfocus.com/archive/1/493020/100/0/threaded
- http://www.securitytracker.com/id?1020166
- http://www.vupen.com/english/advisories/2008/1731
→ the Explorer · watch your stack · NVD