Input validation error in Asterisk Open Source - CVE-2019-15639
Published: September 10, 2019
Vulnerability identifier: #VU20962
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15639
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the "main/translate.c". A remote attacker can send a specific RTP packet during a call and cause a crash in a specific scenario.
Affected software
Asterisk Open Source
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Opensuse
asterisk (Alpine package)
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Opensuse
asterisk (Alpine package)
How to mitigate CVE-2019-15639
Install updates from vendor's website.
Asterisk Open Source - addressed in versions 13.28.1, 16.5.1
asterisk (Alpine package) - update to 16.5.1-r0
asterisk (Alpine package) - update to 16.5.1-r0
External References
Related Security Bulletins
- Slackware Linux update for openssl
- OpenSUSE Linux update for openssl-1_1
- OpenSUSE Linux update for openssl-1_1
- OpenSUSE Linux update for openssl-1_0_0
- OpenSUSE Linux update for openssl-1_0_0
- Gentoo update for OpenSSL
- Amazon Linux AMI update for openssl
- Input validation error in asterisk (Alpine package)