Digium

Asterisk

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 33.11%
  • Veröffentlicht 22.02.2018 00:29:01
  • Zuletzt bearbeitet 21.11.2024 04:11:56

An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).

  • EPSS 72.18%
  • Veröffentlicht 27.12.2017 17:08:20
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if t...

  • EPSS 3.14%
  • Veröffentlicht 13.12.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.

  • EPSS 90.08%
  • Veröffentlicht 02.12.2017 00:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain re...

  • EPSS 3.64%
  • Veröffentlicht 09.11.2017 00:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus,...

  • EPSS 5.27%
  • Veröffentlicht 09.11.2017 00:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets reject...

  • EPSS 0.75%
  • Veröffentlicht 10.10.2017 01:30:21
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined w...

  • EPSS 40.12%
  • Veröffentlicht 02.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.

  • EPSS 0.37%
  • Veröffentlicht 02.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possi...

  • EPSS 34.96%
  • Veröffentlicht 02.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program c...