CVE-2017-16671: Buffer Overflow
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and write past the end of the user field storage buffer. NOTE: this is different from CVE-2017-7617, which was only about the Party A buffer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16671?
CVE-2017-16671 is a Buffer Overflow issue discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1, and Certified Asterisk 13.13 before 13.13-cert7.
What is the severity of CVE-2017-16671?
The severity of CVE-2017-16671 is rated as high with a CVSS score of 8.8.
How does CVE-2017-16671 affect Asterisk Open Source and Certified Asterisk?
CVE-2017-16671 affects Asterisk Open Source versions 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1, as well as Certified Asterisk version 13.13 before 13.13-cert7.
How can I fix CVE-2017-16671?
To fix CVE-2017-16671, upgrade to Asterisk Open Source version 13.18.1 or later, 14.7.1 or later, 15.1.1 or later, or Certified Asterisk version 13.13-cert7 or later.
Where can I find more information about CVE-2017-16671?
More information about CVE-2017-16671 can be found at the following references: [AST-2017-010](http://downloads.digium.com/pub/security/AST-2017-010.html), [AST-2017-010-13.diff](http://downloads.asterisk.org/pub/security/AST-2017-010-13.diff), [ASTERISK-27337](https://issues.asterisk.org/jira/browse/ASTERISK-27337).