Candidate: CVE-2014-9374 PublicDate: 2014-12-12 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9374 http://downloads.digium.com/pub/security/AST-2014-019.html http://downloads.asterisk.org/pub/security/AST-2014-019.html http://www.securitytracker.com/id/1031345 http://secunia.com/advisories/60251 http://seclists.org/fulldisclosure/2014/Dec/48 http://packetstormsecurity.com/files/129473/Asterisk-Project-Security-Advisory-AST-2014-019.html Description: Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773230 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_asterisk: upstream_asterisk: released (11.14.2, 12.7.2, 13.0.2, 11.6-cert9) lucid_asterisk: ignored (reached end-of-life) precise_asterisk: not-affected precise/esm_asterisk: DNE (precise was not-affected) trusty_asterisk: ignored (reached end-of-life) trusty/esm_asterisk: DNE (trusty was needed) utopic_asterisk: ignored (reached end-of-life) vivid_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) vivid/stable-phone-overlay_asterisk: DNE vivid/ubuntu-core_asterisk: DNE wily_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) xenial_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) yakkety_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) zesty_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) artful_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) bionic_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) cosmic_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) disco_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1) devel_asterisk: not-affected (1:13.1.0~dfsg-1ubuntu1)