CVE-2014-9374: Digium Asterisk

Medium severity, CVSS 5.0. EPSS: 9.5% chance of exploitation in the next 30 days.

Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame.

Affected products

  • Digium Asterisk: version 11.0.0 only; version 11.1.0 only; version 11.2.0 only; version 11.3.0 only; version 11.4.0 only; version 11.5.0 only; …
  • Digium Certified Asterisk: version 11.6 only; version 11.6.0 only

Published 2014-12-12. Last modified 2026-06-17.