Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2018-19278 |
CWE-ID | CWE-120 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #1 is available. |
Vulnerable software |
Asterisk Open Source Server applications / Conferencing, Collaboration and VoIP solutions |
Vendor | Digium (Linux Support Services) |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU15900
Risk: Medium
CVSSv4.0: 7.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2018-19278
CWE-ID:
CWE-120 - Buffer overflow
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to buffer overflow in dns_srv and dns_naptr functions when handling malicious input. A remote attacker can supply a specially crafted DNS SRV or NAPTR response, trigger segfault and cause the service to crash.
The vulnerability has been fixed in the version 15.6.2, 16.0.1.
Vulnerable software versionsAsterisk Open Source: 15.0.0 - 16.0.0
CPE2.3https://downloads.asterisk.org/pub/security/AST-2018-010.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.