CVE-2014-6609: Digium Asterisk

Medium severity, CVSS 4.0. EPSS: 3.6% chance of exploitation in the next 30 days.

The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

Affected products

  • Digium Asterisk: version 12.0.0 only; version 12.1.0 only; version 12.2.0 only; version 12.3.0 only; version 12.4.0 only; version 12.5.0 only

Published 2014-11-26. Last modified 2026-06-17.