CVE-2014-2287: Digium Asterisk

Low severity, CVSS 3.5. EPSS: 2.4% chance of exploitation in the next 30 days.

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

Affected products

  • Digium Asterisk: version 1.8.0 only; version 1.8.1 only; version 1.8.1.1 only; version 1.8.1.2 only; version 1.8.2 only; version 1.8.2.1 only; …
  • Digium Certified Asterisk: version 1.8.0.0 only; version 1.8.1.0 only; version 1.8.2.0 only; version 1.8.3.0 only; version 1.8.4.0 only; version 1.8.5.0 only; …
  • Fedoraproject Fedora: version 19 only; version 20 only

Published 2014-04-18. Last modified 2026-06-17.