Candidate: CVE-2014-8416 PublicDate: 2014-11-24 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8416 http://downloads.asterisk.org/pub/security/AST-2014-016.html Description: Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_refer module, allows remote attackers to cause a denial of service (crash) via an in-dialog INVITE with Replaces message, which triggers the channel to be hung up. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Joshua Colp Assigned-to: CVSS: Patches_asterisk: upstream: http://downloads.asterisk.org/pub/security/AST-2014-016-13.diff (13) upstream_asterisk: released (13.0.1) lucid_asterisk: ignored (reached end-of-life) precise_asterisk: not-affected trusty_asterisk: not-affected trusty/esm_asterisk: DNE (trusty was not-affected) utopic_asterisk: not-affected devel_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1)