Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-19278


Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.


Published

2018-11-14T20:29:00.587

Last Modified

2024-11-21T03:57:39.890

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application digium asterisk 15.0.0 Yes
Application digium asterisk 15.0.0 Yes
Application digium asterisk 15.0.0 Yes
Application digium asterisk 15.1.0 Yes
Application digium asterisk 15.1.0 Yes
Application digium asterisk 15.1.0 Yes
Application digium asterisk 15.1.2 Yes
Application digium asterisk 15.1.3 Yes
Application digium asterisk 15.1.4 Yes
Application digium asterisk 15.1.5 Yes
Application digium asterisk 15.2.0 Yes
Application digium asterisk 15.2.0 Yes
Application digium asterisk 15.2.1 Yes
Application digium asterisk 15.2.2 Yes
Application digium asterisk 15.3.0 Yes
Application digium asterisk 15.3.0 Yes
Application digium asterisk 15.3.0 Yes
Application digium asterisk 15.4.0 Yes
Application digium asterisk 15.4.0 Yes
Application digium asterisk 15.4.0 Yes
Application digium asterisk 15.4.1 Yes
Application digium asterisk 15.5.0 Yes
Application digium asterisk 15.5.0 Yes
Application digium asterisk 15.6.0 Yes
Application digium asterisk 15.6.0 Yes
Application digium asterisk 15.6.1 Yes
Application digium asterisk 16.0.0 Yes
Application digium asterisk 16.0.0 Yes
Application digium asterisk 16.0.0 Yes
Application digium asterisk 16.0.1 Yes

References