7.5
CVE-2017-17090
- EPSS 81.51%
- Veröffentlicht 02.12.2017 00:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digium ≫ Certified Asterisk Version <= 13.13
Digium ≫ Certified Asterisk Version 13.13 Update cert1
Digium ≫ Certified Asterisk Version 13.13 Update cert1_rc1
Digium ≫ Certified Asterisk Version 13.13 Update cert1_rc2
Digium ≫ Certified Asterisk Version 13.13 Update cert1_rc3
Digium ≫ Certified Asterisk Version 13.13 Update cert1_rc4
Digium ≫ Certified Asterisk Version 13.13 Update cert2
Digium ≫ Certified Asterisk Version 13.13 Update cert3
Digium ≫ Certified Asterisk Version 13.13 Update cert4
Digium ≫ Certified Asterisk Version 13.13 Update cert5
Digium ≫ Certified Asterisk Version 13.13 Update cert6
Digium ≫ Certified Asterisk Version 13.13 Update cert7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 81.51% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-459 Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
https://www.debian.org/security/2017/dsa-4076
http://downloads.digium.com/pub/security/AST-2017-013.html
http://www.securityfocus.com/bid/102023
http://www.securitytracker.com/id/1039948
https://issues.asterisk.org/jira/browse/ASTERISK-27452
https://lists.debian.org/debian-lts-announce/2017/12/msg00028.html
https://www.exploit-db.com/exploits/43992/