#VU22936 Input validation error in Asterisk Open Source and Certified Asterisk - CVE-2019-18976
Published: November 22, 2019
Asterisk Open Source
Certified Asterisk
Digium (Linux Support Services)
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the "res_pjsip_t38.c" module. A remote attacker can cause a denial of service condition when Asterisk receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP.