Denial of service in Asterisk Open Source - #VU10717

 

Denial of service in Asterisk Open Source - #VU10717

Published: February 26, 2018


Vulnerability identifier: #VU10717
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The weakness exists due to insufficient validation of Session Description Protocol (SDP) messages. A remote attacker can submit a specially crafted SDP message, which contains an improper fmtp attribute and cause the service to crash.

Affected software

Asterisk Open Source

Remediation

Update to version 13.19.2, 14.7.6, 15.2.2.


External References

Related Security Bulletins