7.5
CVE-2017-9358
- EPSS 2.82%
- Veröffentlicht 02.06.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asterisk ≫ Certified Asterisk Version 13.13.0
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc1
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc2
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc3
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert1-rc4
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert2
Asterisk ≫ Certified Asterisk Version 13.13.0 Update cert3
Asterisk ≫ Certified Asterisk Version 13.13.0 Update rc1
Asterisk ≫ Certified Asterisk Version 13.13.0 Update rc2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.82% | 0.847 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
http://downloads.asterisk.org/pub/security/AST-2017-004.txt
http://www.securityfocus.com/bid/98573
http://www.securitytracker.com/id/1038531
https://bugs.debian.org/863906