SB2017052303 - Multiple vulnerabilities in Digium Asterisk



SB2017052303 - Multiple vulnerabilities in Digium Asterisk

Published: May 23, 2017

Security Bulletin ID SB2017052303
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Memory corruption (CVE-ID: N/A)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to insufficient bounds checking. A remote attacker can send a specially crafted Skinny Client Control Protocol (SCCP) packet, trigger memory corruption and cause the affected device to crash.

Successful exploitation of the vulnerability results in denial of service.

2) Memory corruption (CVE-ID: N/A)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to insufficient allocation of a buffer size by the PJSIP RFC 2543 transaction key generation algorithm. A remote attacker can send a specially crafted Session Initiation Protocol (SIP) packet containing a long CSeq header value along with a Via header with no branch parameter, trigger memory corruption and cause the affected device to crash.

Successful exploitation of the vulnerability results in denial of service.

3) Out-of-bounds read (CVE-ID: N/A)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper memory read. A remote attacker can send a specially crafted packet containing a long CSeq header value along with a Via header with no branch parameter, trigger an out-of-bounds memory read and cause the affected system to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Install update from vendor's website.