CVE-2014-6610: Digium Asterisk
Medium severity, CVSS 4.0. EPSS: 1.5% chance of exploitation in the next 30 days.
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.
Affected products
- Digium Asterisk: version 11.0.0 only; version 11.1.0 only; version 11.2.0 only; version 11.3.0 only; version 11.4.0 only; version 11.5.0 only; …
- Digium Certified Asterisk: version 11.6 only; version 11.6.0 only
Published 2014-11-26. Last modified 2026-06-17.