8.2

CVE-2023-37457

Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. A patch is available at commit a1ca0268254374b515fa5992f01340f7717113fa.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digium ≫ Asterisk Version <= 18.20.0
Digium ≫ Asterisk Version >= 19.0.0 <= 20.5.0
Digium ≫ Asterisk Version 21.0.0
Sangoma ≫ Certified Asterisk Version 13.13.0
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc2
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc3
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc4
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert2
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert3
Sangoma ≫ Certified Asterisk Version 13.13.0 Update rc1
Sangoma ≫ Certified Asterisk Version 13.13.0 Update rc2
Sangoma ≫ Certified Asterisk Version 16.8.0 Update -
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert1
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert10
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert11
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert12
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert2
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert3
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert4
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert5
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert6
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert7
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert8
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert9
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert3
Sangoma ≫ Certified Asterisk Version 18.9 Update cert4
Sangoma ≫ Certified Asterisk Version 18.9 Update cert5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.13% 0.621
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://lists.debian.org/debian-lts-announce/2023/12/msg00019.html
https://github.com/asterisk/asterisk/commit/a1ca0268254374b515fa5992f01340f7717113fa
Patch
https://github.com/asterisk/asterisk/security/advisories/GHSA-98rc-4j27-74hh
Vendor Advisory