Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18976

Опубликовано: 22 нояб. 2019
Источник: debian

Описание

An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
asteriskfixed1:16.1.1~dfsg-1package
asterisknot-affectedjessiepackage

Примечания

  • https://downloads.asterisk.org/pub/security/AST-2019-008.html

  • https://issues.asterisk.org/jira/browse/ASTERISK-28612

  • Only affects 13.x, marking first unstable upload after 13.x as fixed

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.

CVSS3: 7.5
nvd
около 6 лет назад

An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость компонента res_pjsip_t38.c систем управления IP-телефонией Asterisk и Certified Asterisk, позволяющая нарушителю вызвать отказ в обслуживании

Уязвимость CVE-2019-18976