PT-2019-5836 · Digium · Asterisk+1

Salah Ahmed

·

Published

2019-11-22

·

Updated

2022-06-03

·

CVE-2019-18976

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Asterisk versions prior to 13.21-x Certified Asterisk versions prior to 13.21-x
Description The issue is related to a null pointer dereference in the res pjsip t38.c component of Asterisk and Certified Asterisk systems. This can be exploited by a remote attacker to cause a denial of service. The vulnerability is triggered when the system receives a re-invite for T.38 faxing with a port of 0 and no c line in the SDP.
Recommendations For Asterisk versions prior to 13.21-x, update to version 13.21-x or later to resolve the issue. For Certified Asterisk versions prior to 13.21-x, update to version 13.21-x or later to resolve the issue. As a temporary workaround, consider restricting access to the res pjsip t38.c component until a patch is available.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03298
CVE-2019-18976
DLA-2969-1

Affected Products

Asterisk
Certified Asterisk