RULE(RULE ID:315758)

Rule General Information
Release Date: 2016-05-02
Rule Name: Digium Asterisk Cookie Stack Overflow Vulnerability -2 (CVE-2014-2286)
Severity:
CVE ID:
Rule Protection Details
Description: main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows
Reference: SecurityFocusBID:66093
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://downloads.asterisk.org/pub/security/AST-2014-001.pdf