Candidate: CVE-2009-2651 PublicDate: 2009-07-30 20:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2651 http://downloads.asterisk.org/pub/security/AST-2009-004.html Description: main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_asterisk: upstream_asterisk: needs-triage dapper_asterisk: ignored (reached end-of-life) hardy_asterisk: not-affected intrepid_asterisk: needed (reached end-of-life) jaunty_asterisk: ignored (reached end-of-life) karmic_asterisk: not-affected (1:1.6.2.0~rc2-0ubuntu1) lucid_asterisk: not-affected (1:1.6.2.0~rc2-0ubuntu1) maverick_asterisk: not-affected (1:1.6.2.0~rc2-0ubuntu1) natty_asterisk: not-affected (1:1.6.2.0~rc2-0ubuntu1) devel_asterisk: not-affected (1:1.6.2.0~rc2-0ubuntu1)