Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.140493
Category:Denial of Service
Title:Asterisk pjproject Header DoS Vulnerability
Summary:Asterisk is prone to a buffer overflow vulnerability which leads; to a denial of service.
Description:Summary:
Asterisk is prone to a buffer overflow vulnerability which leads
to a denial of service.

Vulnerability Insight:
By carefully crafting invalid values in the Cseq and the Via
header port, pjproject's packet parsing code can create strings larger than the buffer allocated to
hold them. This will usually cause Asterisk to crash immediately. The packets do not have to be
authenticated.

Vulnerability Impact:
An unauthenticated remote attacker may crash Asterisk leading to a
denial of service condition.

Affected Software/OS:
Asterisk Open Source 13.x, 14.x, 15.x and Certified Asterisk
13.13.

Solution:
Update to version 13.18.1, 14.7.1, 15.1.1, 13.13-cert7 or
later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.