Candidate: CVE-2014-8415 PublicDate: 2014-11-24 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8415 http://downloads.asterisk.org/pub/security/AST-2014-015.html Description: Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a cancel request for a SIP session with a queued action to (1) answer a session or (2) send ringing. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Yaron Nahum Assigned-to: CVSS: Patches_asterisk: upstream: http://downloads.asterisk.org/pub/security/AST-2014-015-13.diff (13) upstream_asterisk: released (13.0.1) lucid_asterisk: ignored (reached end-of-life) precise_asterisk: not-affected trusty_asterisk: not-affected trusty/esm_asterisk: DNE (trusty was not-affected) utopic_asterisk: not-affected devel_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1)