CVE-2012-2415: Asterisk Open Source

Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated users to cause a denial of service or possibly have unspecified other impact via a series of KEYPAD_BUTTON_MESSAGE events.

Affected products

  • Asterisk Open Source: version 1.6.2.0 only; version 1.6.2.1 only; version 1.6.2.2 only; version 1.6.2.3 only; version 1.6.2.4 only; version 1.6.2.5 only; …

Published 2012-04-30. Last modified 2026-06-16.