Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | N/A |
CWE-ID | CWE-119 CWE-125 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Asterisk Open Source Server applications / Conferencing, Collaboration and VoIP solutions Certified Asterisk Server applications / Conferencing, Collaboration and VoIP solutions |
Vendor | Digium (Linux Support Services) |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU6618
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to insufficient bounds checking. A remote attacker can send a specially crafted Skinny Client Control Protocol (SCCP) packet, trigger memory corruption and cause the affected device to crash.
Successful exploitation of the vulnerability results in denial of service.
Update Asterisk to version 13.15.1 and 14.4.1.
Update Certified Asterisk to version 13.13-cert.
Asterisk Open Source: 13.0.1 - 14.4.0
Certified Asterisk: 13.13
CPE2.3https://downloads.asterisk.org/pub/security/AST-2017-004.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU6619
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to insufficient allocation of a buffer size by the PJSIP RFC 2543 transaction key generation algorithm. A remote attacker can send a specially crafted Session Initiation Protocol (SIP) packet containing a long CSeq header value along with a Via header with no branch parameter, trigger memory corruption and cause the affected device to crash.
Successful exploitation of the vulnerability results in denial of service.
Update Asterisk to version 13.15.1 and 14.4.1.
Update Certified Asterisk to version 13.13-cert.
Asterisk Open Source: 13.0.1 - 14.4.0
Certified Asterisk: 13.13
CPE2.3https://downloads.asterisk.org/pub/security/AST-2017-002.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU6620
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper memory read. A remote attacker can send a specially crafted packet containing a long CSeq header value along with a Via header with no branch parameter, trigger an out-of-bounds memory read and cause the affected system to crash.
Successful exploitation of the vulnerability results in denial of service.
Update Asterisk to version 13.15.1 and 14.4.1.
Update Certified Asterisk to version 13.13-cert.
Asterisk Open Source: 13.0.1 - 14.4.0
Certified Asterisk: 13.13
CPE2.3https://downloads.asterisk.org/pub/security/AST-2017-003.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.