CVE-2018-7287Improper Check for Unusual or Exceptional Conditions in Asterisk

Severity
5.9MEDIUMNVD
EPSS
33.1%
top 3.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 13

Description

An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDdigium/asterisk9 versions+8

🔴Vulnerability Details

1
GHSA
GHSA-38rg-6v6g-2qmq: An issue was discovered in res_http_websocket2022-05-13

📋Vendor Advisories

1
Debian
CVE-2018-7287: asterisk - An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1....2018

💬Community

3
Bugzilla
CVE-2018-7287 asterisk: Denial of Service (DoS) in WebSocket frames with 0 sized payload [fedora-all]2018-02-22
Bugzilla
CVE-2018-7287 asterisk: Denial of Service (DoS) in WebSocket frames with 0 sized payload2018-02-22
Bugzilla
CVE-2018-7287 asterisk: Denial of Service (DoS) in WebSocket frames with 0 sized payload [epel-6]2018-02-22