An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request.
2021-07-30T14:15:16.690
2024-11-21T06:06:24.867
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | digium | asterisk | 16.17.0 | Yes |
Application | digium | asterisk | 16.18.0 | Yes |
Application | digium | asterisk | 16.19.0 | Yes |
Application | digium | asterisk | 18.3.0 | Yes |
Application | digium | asterisk | 18.4.0 | Yes |
Application | digium | asterisk | 18.5.0 | Yes |