Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Janhoffmann

#37779of 53,611
7.5Total CVSS
Vulnerabilities · 1
PT-2018-14899
7.5
2018-11-14
Digium · Asterisk · CVE-2018-19278
**Name of the Vulnerable Software and Affected Versions** Digium Asterisk versions 15.x through 15.6.1 Digium Asterisk versions 16.x through 16.0.0 **Description** A buffer overflow issue exists in the DNS SRV and NAPTR lookups. This allows remote attackers to crash the system via a specially crafted DNS SRV or NAPTR response. The issue arises because a buffer size is supposed to match an expanded length but actually matches a compressed length. **Recommendations** For Digium Asterisk versions 15.x through 15.6.1, update to version 15.6.2 or later. For Digium Asterisk versions 16.x through 16.0.0, update to version 16.0.1 or later.