Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37457


Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. A patch is available at commit a1ca0268254374b515fa5992f01340f7717113fa.


Published

2023-12-14T20:15:52.260

Last Modified

2024-11-21T08:11:44.807

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-120
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application digium asterisk ≤ 18.20.0 Yes
Application digium asterisk ≤ 20.5.0 Yes
Application digium asterisk 21.0.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 13.13.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 16.8.0 Yes
Application sangoma certified_asterisk 18.9 Yes
Application sangoma certified_asterisk 18.9 Yes
Application sangoma certified_asterisk 18.9 Yes
Application sangoma certified_asterisk 18.9 Yes
Application sangoma certified_asterisk 18.9 Yes

References