Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
2019-07-12T20:15:11.063
2024-11-21T04:23:40.063
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | digium | asterisk | < 13.27.0 | Yes |
Application | digium | asterisk | < 15.7.2 | Yes |
Application | digium | asterisk | < 16.4.0 | Yes |
Application | digium | certified_asterisk | 13.21 | Yes |
Application | digium | certified_asterisk | 13.21 | Yes |
Application | digium | certified_asterisk | 13.21 | Yes |
Application | digium | certified_asterisk | 13.21 | Yes |
Application | digium | certified_asterisk | 13.21 | Yes |