Digium Asterisk vulnerabilities

114 known vulnerabilities affecting digium/asterisk.

Total CVEs
114
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH37MEDIUM67LOW5

Vulnerabilities

Page 2 of 6
CVE-2019-12827MEDIUMCVSS 6.5≥ 13.0.0, < 13.27.0≥ 15.0.0, < 15.7.2+1 more2019-07-12
CVE-2019-12827 [MEDIUM] CWE-787 CVE-2019-12827: Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16. Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
nvdosv
CVE-2019-13161MEDIUMCVSS 5.3≥ 13.0.0, < 13.27.1≥ 15.0.0, < 15.7.3+1 more2019-07-12
CVE-2019-13161 [MEDIUM] CWE-476 CVE-2019-13161: An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 1 An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerabil
nvdosv
CVE-2016-7550HIGHCVSS 7.5v13.10.02019-05-23
CVE-2016-7550 [HIGH] CWE-476 CVE-2016-7550: asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).
nvdosv
CVE-2019-7251MEDIUMCVSS 6.5≥ 15.0.0, < 15.7.2≥ 16.0.0, < 16.2.12019-03-28
CVE-2019-7251 [MEDIUM] CWE-190 CVE-2019-7251: An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk v An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation.
nvdosv
CVE-2018-19278HIGHCVSS 7.5v15.0.0v15.1.0+15 more2018-11-14
CVE-2018-19278 [HIGH] CWE-119 CVE-2018-19278: Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 1 Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
nvdosv
CVE-2018-17281HIGHCVSS 7.5≥ 13.0.0, ≤ 13.23.0≥ 14.0.0, ≤ 14.7.7+1 more2018-09-24
CVE-2018-17281 [HIGH] CWE-400 CVE-2018-17281: There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 1 There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.
nvdosv
CVE-2018-12227MEDIUMCVSS 5.3≥ 13.0.0, < 13.21.1fixed in 14.7.7+1 more2018-06-12
CVE-2018-12227 [MEDIUM] CWE-200 CVE-2018-12227: An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x be An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not identified, then a 401 unauthor
nvdosv
CVE-2018-7284HIGHCVSS 7.5PoC≤ 13.19.1≥ 14.0.0, ≤ 14.7.5+1 more2018-02-22
CVE-2018-7284 [HIGH] CWE-119 CVE-2018-7284: A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x th A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not limit the number of headers it processed
nvdosv
CVE-2018-7285HIGHCVSS 7.5≥ 15.0.0, ≤ 15.2.12018-02-22
CVE-2018-7285 [HIGH] CWE-476 CVE-2018-7285: A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Aster A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs and desired payload numbers. While an SDP negotiation may result in a codec using a different payload number, these desired ones are still stored internally. When an RTP packet was received, this registry w
nvd
CVE-2018-7286MEDIUMCVSS 6.5PoC≥ 14.0.0, ≤ 14.7.5≥ 15.0.0, ≤ 15.2.1+1 more2018-02-22
CVE-2018-7286 [MEDIUM] CVE-2018-7286: An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, a An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.
nvdosv
CVE-2018-7287MEDIUMCVSS 5.9v15.0.0v15.1.0+7 more2018-02-22
CVE-2018-7287 [MEDIUM] CWE-754 CVE-2018-7287: An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).
nvd
CVE-2017-17850HIGHCVSS 7.5≥ 13.0.0, ≤ 13.18.4≥ 14.0.0, ≤ 14.7.4+1 more2017-12-27
CVE-2017-17850 [HIGH] CWE-20 CVE-2017-17850: An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18 An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used, Asterisk would crash. The severity of t
nvdosv
CVE-2017-17664MEDIUMCVSS 5.9≥ 13.0.0, < 13.18.4≥ 14.0.0, < 14.7.4+1 more2017-12-13
CVE-2017-17664 [MEDIUM] CWE-119 CVE-2017-17664: A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.
nvdosv
CVE-2017-17090HIGHCVSS 7.5PoC≤ 13.8.2≤ 14.7.2+1 more2017-12-02
CVE-2017-17090 [HIGH] CWE-459 CVE-2017-17090: An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causin
nvdosv
CVE-2017-16671HIGHCVSS 8.8≥ 13.0.0, < 13.18.1≥ 14.0.0, < 14.7.1+1 more2017-11-09
CVE-2017-16671 [HIGH] CWE-119 CVE-2017-16671: A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and write past the end of the user field
nvdosv
CVE-2017-16672MEDIUMCVSS 5.9≥ 13.0.0, < 13.18.1≥ 14.0.0, < 14.7.1+1 more2017-11-09
CVE-2017-16672 [MEDIUM] CWE-772 CVE-2017-16672: An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 1 An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens the session object never gets de
nvdosv
CVE-2017-14603HIGHCVSS 7.5v13.0.0v13.0.1+99 more2017-10-10
CVE-2017-14603 [HIGH] CWE-200 CVE-2017-14603: In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and "symmetric_rtp" options allow redirecting where Asterisk sends the next RTCP report.
nvdosv
CVE-2017-14100CRITICALCVSS 9.8v13.0.0v13.0.1+99 more2017-09-02
CVE-2017-14100 [CRITICAL] CWE-78 CVE-2017-14100: In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan application. The application uses t
nvdosv
CVE-2017-14098HIGHCVSS 7.5v13.0.0v13.0.1+54 more2017-09-02
CVE-2017-14098 [HIGH] CWE-20 CVE-2017-14098: In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a ca In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
nvdosv
CVE-2017-14099HIGHCVSS 7.5v13.0.0v13.0.1+99 more2017-09-02
CVE-2017-14099 [HIGH] CWE-200 CVE-2017-14099: In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6 In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The "strictrtp" option in rtp.conf enables a feature of the RTP
nvdosv