CVE-2017-14603: Infoleak
In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and "symmetricrtp" options allow redirecting where Asterisk sends the next RTCP report.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14603?
The severity of CVE-2017-14603 is classified as high.
How do I fix CVE-2017-14603?
To fix CVE-2017-14603, upgrade to Asterisk versions 11.25.3, 13.17.2, or 14.6.2 or later.
What versions of Asterisk are affected by CVE-2017-14603?
CVE-2017-14603 affects Asterisk versions 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2.
What type of vulnerability is CVE-2017-14603?
CVE-2017-14603 is a vulnerability related to insufficient RTCP packet validation.
Can CVE-2017-14603 lead to data exposure?
Yes, CVE-2017-14603 can lead to data exposure by allowing reading of stale buffer contents.