Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Seanbright

#20260of 53,624
12.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-11059
6.8
2018-06-12
Sangoma · Asterisk Open Source · CVE-2018-12228
**Name of the Vulnerable Software and Affected Versions** Asterisk Open Source versions 15.x before 15.4.1 **Description** An issue was discovered in Asterisk Open Source. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read the data stream. This renders the system unusable. **Recommendations** For Asterisk Open Source versions 15.x before 15.4.1, update to version 15.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the TCP/TLS connection to minimize the risk of exploitation.
PT-2018-18001
5.9
2018-02-22
Sangoma · Asterisk · CVE-2018-7287
**Name of the Vulnerable Software and Affected Versions** Asterisk versions 15.x through 15.2.1 **Description** An issue in the `res http websocket.c` file causes the Asterisk system to mishandle WebSocket payloads of size 0, resulting in a busy loop when the HTTP server is enabled. **Recommendations** For Asterisk versions 15.x through 15.2.1, consider disabling the HTTP server as a temporary workaround to minimize the risk of exploitation.