Vulnerability Details CVE-2014-9374
Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.491
EPSS Ranking 97.6%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2014-9374
-
cpe:2.3:a:digium:asterisk:11.0.0
-
cpe:2.3:a:digium:asterisk:11.1.0
-
cpe:2.3:a:digium:asterisk:11.10.0
-
cpe:2.3:a:digium:asterisk:11.11.0
-
cpe:2.3:a:digium:asterisk:11.12.0
-
cpe:2.3:a:digium:asterisk:11.13.0
-
cpe:2.3:a:digium:asterisk:11.14.0
-
cpe:2.3:a:digium:asterisk:11.2.0
-
cpe:2.3:a:digium:asterisk:11.3.0
-
cpe:2.3:a:digium:asterisk:11.4.0
-
cpe:2.3:a:digium:asterisk:11.5.0
-
cpe:2.3:a:digium:asterisk:11.6.0
-
cpe:2.3:a:digium:asterisk:11.7.0
-
cpe:2.3:a:digium:asterisk:11.8.0
-
cpe:2.3:a:digium:asterisk:11.9.0
-
cpe:2.3:a:digium:asterisk:12.0.0
-
cpe:2.3:a:digium:asterisk:12.1.0
-
cpe:2.3:a:digium:asterisk:12.2.0
-
cpe:2.3:a:digium:asterisk:12.3.0
-
cpe:2.3:a:digium:asterisk:12.4.0
-
cpe:2.3:a:digium:asterisk:12.5.0
-
cpe:2.3:a:digium:asterisk:12.6.0
-
cpe:2.3:a:digium:asterisk:12.7.0
-
cpe:2.3:a:digium:asterisk:12.7.1
-
cpe:2.3:a:digium:asterisk:13.0.0
-
cpe:2.3:a:digium:asterisk:13.0.1
-
cpe:2.3:a:digium:certified_asterisk:11.6
-
cpe:2.3:a:digium:certified_asterisk:11.6.0