Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-13161


An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chan_sip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).


Published

2019-07-12T20:15:11.127

Last Modified

2024-11-21T04:24:19.633

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.0.0 Yes
Application digium certified_asterisk 1.8.1.0 Yes
Application digium certified_asterisk 1.8.1.0 Yes
Application digium certified_asterisk 1.8.2.0 Yes
Application digium certified_asterisk 1.8.2.0 Yes
Application digium certified_asterisk 1.8.3.0 Yes
Application digium certified_asterisk 1.8.3.0 Yes
Application digium certified_asterisk 1.8.3.0 Yes
Application digium certified_asterisk 1.8.3.0 Yes
Application digium certified_asterisk 1.8.4.0 Yes
Application digium certified_asterisk 1.8.4.0 Yes
Application digium certified_asterisk 1.8.4.0 Yes
Application digium certified_asterisk 1.8.4.0 Yes
Application digium certified_asterisk 1.8.5.0 Yes
Application digium certified_asterisk 1.8.5.0 Yes
Application digium certified_asterisk 1.8.6.0 Yes
Application digium certified_asterisk 1.8.6.0 Yes
Application digium certified_asterisk 1.8.6.0 Yes
Application digium certified_asterisk 1.8.6.0 Yes
Application digium certified_asterisk 1.8.7.0 Yes
Application digium certified_asterisk 1.8.7.0 Yes
Application digium certified_asterisk 1.8.7.0 Yes
Application digium certified_asterisk 1.8.8.0 Yes
Application digium certified_asterisk 1.8.8.0 Yes
Application digium certified_asterisk 1.8.8.0 Yes
Application digium certified_asterisk 1.8.8.0 Yes
Application digium certified_asterisk 1.8.8.0 Yes
Application digium certified_asterisk 1.8.8.0 Yes
Application digium certified_asterisk 1.8.9.0 Yes
Application digium certified_asterisk 1.8.9.0 Yes
Application digium certified_asterisk 1.8.9.0 Yes
Application digium certified_asterisk 1.8.9.0 Yes
Application digium certified_asterisk 1.8.10.0 Yes
Application digium certified_asterisk 1.8.10.0 Yes
Application digium certified_asterisk 1.8.10.0 Yes
Application digium certified_asterisk 1.8.10.0 Yes
Application digium certified_asterisk 1.8.10.0 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11 Yes
Application digium certified_asterisk 1.8.11.0 Yes
Application digium certified_asterisk 1.8.11.0 Yes
Application digium certified_asterisk 1.8.11.0 Yes
Application digium certified_asterisk 1.8.11.0 Yes
Application digium certified_asterisk 1.8.12.0 Yes
Application digium certified_asterisk 1.8.12.0 Yes
Application digium certified_asterisk 1.8.12.0 Yes
Application digium certified_asterisk 1.8.12.0 Yes
Application digium certified_asterisk 1.8.13.0 Yes
Application digium certified_asterisk 1.8.13.0 Yes
Application digium certified_asterisk 1.8.13.0 Yes
Application digium certified_asterisk 1.8.14.0 Yes
Application digium certified_asterisk 1.8.14.0 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.15 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28 Yes
Application digium certified_asterisk 1.8.28.0 Yes
Application digium certified_asterisk 11.0.0 Yes
Application digium certified_asterisk 11.0.0 Yes
Application digium certified_asterisk 11.0.0 Yes
Application digium certified_asterisk 11.1.0 Yes
Application digium certified_asterisk 11.1.0 Yes
Application digium certified_asterisk 11.1.0 Yes
Application digium certified_asterisk 11.1.0 Yes
Application digium certified_asterisk 11.2 Yes
Application digium certified_asterisk 11.2 Yes
Application digium certified_asterisk 11.2 Yes
Application digium certified_asterisk 11.2 Yes
Application digium certified_asterisk 11.3.0 Yes
Application digium certified_asterisk 11.3.0 Yes
Application digium certified_asterisk 11.3.0 Yes
Application digium certified_asterisk 11.4.0 Yes
Application digium certified_asterisk 11.4.0 Yes
Application digium certified_asterisk 11.4.0 Yes
Application digium certified_asterisk 11.4.0 Yes
Application digium certified_asterisk 11.5.0 Yes
Application digium certified_asterisk 11.5.0 Yes
Application digium certified_asterisk 11.5.0 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6 Yes
Application digium certified_asterisk 11.6.0 Yes
Application digium certified_asterisk 11.6.0 Yes
Application digium certified_asterisk 11.6.0 Yes
Application digium certified_asterisk 11.6.0 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1 Yes
Application digium certified_asterisk 13.1.0 Yes
Application digium certified_asterisk 13.1.0 Yes
Application digium certified_asterisk 13.1.0 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8 Yes
Application digium certified_asterisk 13.8.0 Yes
Application digium certified_asterisk 13.8.0 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13 Yes
Application digium certified_asterisk 13.13-cert2 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.18 Yes
Application digium certified_asterisk 13.21 Yes
Application digium certified_asterisk 13.21 Yes
Application digium certified_asterisk 13.21 Yes
Application digium certified_asterisk 13.21 Yes
Application digium certified_asterisk 13.21 Yes
Application digium asterisk < 13.27.1 Yes
Application digium asterisk < 15.7.3 Yes
Application digium asterisk < 16.4.1 Yes
Operating System debian debian_linux 8.0 Yes
Operating System debian debian_linux 9.0 Yes

References