SB2017052303 - Multiple vulnerabilities in Digium Asterisk
Published: May 23, 2017
Security Bulletin ID
SB2017052303
Severity
Medium
Patch available
YES
Number of vulnerabilities
3
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Memory corruption (CVE-ID: N/A)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to insufficient bounds checking. A remote attacker can send a specially crafted Skinny Client Control Protocol (SCCP) packet, trigger memory corruption and cause the affected device to crash.
Successful exploitation of the vulnerability results in denial of service.
2) Memory corruption (CVE-ID: N/A)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to insufficient allocation of a buffer size by the PJSIP RFC 2543 transaction key generation algorithm. A remote attacker can send a specially crafted Session Initiation Protocol (SIP) packet containing a long CSeq header value along with a Via header with no branch parameter, trigger memory corruption and cause the affected device to crash.
Successful exploitation of the vulnerability results in denial of service.
3) Out-of-bounds read (CVE-ID: N/A)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to improper memory read. A remote attacker can send a specially crafted packet containing a long CSeq header value along with a Via header with no branch parameter, trigger an out-of-bounds memory read and cause the affected system to crash.
Successful exploitation of the vulnerability results in denial of service.
Remediation
Install update from vendor's website.