#VU96902 NULL pointer dereference in Certified Asterisk and Asterisk Open Source - CVE-2024-42491
Published: September 5, 2024
Certified Asterisk
Asterisk Open Source
Digium (Linux Support Services)
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when handling malformed Contact or Record-Route URI in an incoming SIP request. A remote attacker can send a specially crafted SIP request to the server and perform a denial of service (DoS) attack.