Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-17281

Опубликовано: 24 сент. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Высокий

Описание

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:digium:asterisk:*:*:*:*:lts:*:*:*
Версия от 13.0.0 (включая) до 13.23.0 (включая)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Версия от 14.0.0 (включая) до 14.7.7 (включая)
cpe:2.3:a:digium:asterisk:*:*:*:*:standard:*:*:*
Версия от 15.0.0 (включая) до 15.6.0 (включая)
Конфигурация 2

Одно из

cpe:2.3:a:digium:certified_asterisk:11.6:cert12:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert13:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert14:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert15:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert16:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert17:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert18:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert3:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert4:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert5:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert6:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert7:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert8:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.8:cert1:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.8:cert2:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.8:cert3:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.8:cert4:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert5:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert6:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert7:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert8:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert9:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.21:cert1:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.21:cert2:*:*:lts:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.80258
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.

CVSS3: 7.5
debian
больше 7 лет назад

There is a stack consumption vulnerability in the res_http_websocket.s ...

CVSS3: 7.5
github
больше 3 лет назад

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.

EPSS

Процентиль: 99%
0.80258
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400