7.5

CVE-2017-9358

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sangoma ≫ Asterisk Version 13.0.0
Sangoma ≫ Asterisk Version 13.1.0
Sangoma ≫ Asterisk Version 13.1.0 Update rc1
Sangoma ≫ Asterisk Version 13.1.0 Update rc2
Sangoma ≫ Asterisk Version 13.2.0
Sangoma ≫ Asterisk Version 13.2.0 Update rc1
Sangoma ≫ Asterisk Version 13.3.0 Update rc1
Sangoma ≫ Asterisk Version 13.4.0
Sangoma ≫ Asterisk Version 13.4.0 Update rc1
Sangoma ≫ Asterisk Version 13.5.0
Sangoma ≫ Asterisk Version 13.5.0 Update rc1
Sangoma ≫ Asterisk Version 13.6.0 Update rc1
Sangoma ≫ Asterisk Version 13.7.0
Sangoma ≫ Asterisk Version 13.7.0 Update rc1
Sangoma ≫ Asterisk Version 13.8.0
Sangoma ≫ Asterisk Version 13.8.0 Update rc1
Sangoma ≫ Asterisk Version 13.8.1
Sangoma ≫ Asterisk Version 13.8.2
Sangoma ≫ Asterisk Version 13.9.0
Sangoma ≫ Asterisk Version 13.9.0 Update rc1
Sangoma ≫ Asterisk Version 13.10.0 Update rc1
Sangoma ≫ Asterisk Version 13.11.0 Update rc1
Sangoma ≫ Asterisk Version 13.12.0
Sangoma ≫ Asterisk Version 13.12.0 Update rc1
Sangoma ≫ Asterisk Version 13.12.1
Sangoma ≫ Asterisk Version 13.12.2
Sangoma ≫ Asterisk Version 13.13.0 Update rc1
Sangoma ≫ Asterisk Version 13.14.0 Update rc1
Sangoma ≫ Asterisk Version 13.15.0 Update rc1
Asterisk ≫ Certified Asterisk Version 13.13.0
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc1
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc2
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc3
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc4
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert2
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert3
Asterisk ≫ Certified Asterisk Version 13.13.0 Update rc1
Asterisk ≫ Certified Asterisk Version 13.13.0 Update rc2
Sangoma ≫ Asterisk Version 14.0.0
Sangoma ≫ Asterisk Version 14.0.0 Update beta1
Sangoma ≫ Asterisk Version 14.0.0 Update beta2
Sangoma ≫ Asterisk Version 14.0.0 Update rc1
Sangoma ≫ Asterisk Version 14.1.0 Update rc1
Sangoma ≫ Asterisk Version 14.2.0
Sangoma ≫ Asterisk Version 14.2.0 Update rc1
Sangoma ≫ Asterisk Version 14.2.0 Update rc2
Sangoma ≫ Asterisk Version 14.2.1
Sangoma ≫ Asterisk Version 14.3.0 Update rc1
Sangoma ≫ Asterisk Version 14.4.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.82% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

http://downloads.asterisk.org/pub/security/AST-2017-004.txt
Third Party Advisory
http://www.securityfocus.com/bid/98573
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038531
https://bugs.debian.org/863906
Third Party Advisory
Mailing List