SB2021022612 - Improper Resource Shutdown or Release in asterisk (Alpine package)



SB2021022612 - Improper Resource Shutdown or Release in asterisk (Alpine package)

Published: February 26, 2021

Security Bulletin ID SB2021022612
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Resource Shutdown or Release (CVE-ID: CVE-2021-26906)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.


Remediation

Install update from vendor's website.