First published: Thu Nov 09 2017(Updated: )
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and write past the end of the user field storage buffer. NOTE: this is different from CVE-2017-7617, which was only about the Party A buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/asterisk | 1:16.2.1~dfsg-1+deb10u2 1:16.28.0~dfsg-0+deb10u3 1:16.28.0~dfsg-0+deb11u3 1:20.4.0~dfsg+~cs6.13.40431414-2 | |
Asterisk | >=13.0.0<13.18.1 | |
Asterisk | >=14.0.0<14.7.1 | |
Asterisk | >=15.0.0<15.1.1 | |
Asterisk Certified Asterisk | =13.13.0 | |
Asterisk Certified Asterisk | =13.13.0-cert1 | |
Asterisk Certified Asterisk | =13.13.0-cert1_rc1 | |
Asterisk Certified Asterisk | =13.13.0-cert1_rc2 | |
Asterisk Certified Asterisk | =13.13.0-cert1_rc3 | |
Asterisk Certified Asterisk | =13.13.0-cert1_rc4 | |
Asterisk Certified Asterisk | =13.13.0-cert2 | |
Asterisk Certified Asterisk | =13.13.0-cert3 | |
Asterisk Certified Asterisk | =13.13.0-cert4 | |
Asterisk Certified Asterisk | =13.13.0-cert5 | |
Asterisk Certified Asterisk | =13.13.0-cert6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16671 is a Buffer Overflow issue discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1, and Certified Asterisk 13.13 before 13.13-cert7.
The severity of CVE-2017-16671 is rated as high with a CVSS score of 8.8.
CVE-2017-16671 affects Asterisk Open Source versions 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1, as well as Certified Asterisk version 13.13 before 13.13-cert7.
To fix CVE-2017-16671, upgrade to Asterisk Open Source version 13.18.1 or later, 14.7.1 or later, 15.1.1 or later, or Certified Asterisk version 13.13-cert7 or later.
More information about CVE-2017-16671 can be found at the following references: [AST-2017-010](http://downloads.digium.com/pub/security/AST-2017-010.html), [AST-2017-010-13.diff](http://downloads.asterisk.org/pub/security/AST-2017-010-13.diff), [ASTERISK-27337](https://issues.asterisk.org/jira/browse/ASTERISK-27337).