NULL pointer dereference in Asterisk Open Source and Certified Asterisk - CVE-2024-42491
Published: September 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when handling malformed Contact or Record-Route URI in an incoming SIP request. A remote attacker can send a specially crafted SIP request to the server and perform a denial of service (DoS) attack.
Affected software
Certified Asterisk
How to mitigate CVE-2024-42491
Certified Asterisk - addressed in versions 18.9-cert12, 20.7-cert3