CVE-2017-17090: High severity Digium Asterisk Appliance Developer Kit vulnerability
An issue was discovered in chanskinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chanskinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17090?
The severity of CVE-2017-17090 is high.
How does CVE-2017-17090 affect Asterisk Open Source?
CVE-2017-17090 affects Asterisk Open Source versions 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older.
What is the remedy for CVE-2017-17090?
The remedy for CVE-2017-17090 is to update Asterisk Open Source to version 13.13-cert7 and older, or 1:16.2.1~dfsg-1+deb10u2, 1:16.28.0~dfsg-0+deb10u3, 1:16.28.0~dfsg-0+deb11u3, 1:20.4.0~dfsg+~cs6.13.40431414-2 or newer.
Where can I find more information about CVE-2017-17090?
You can find more information about CVE-2017-17090 at the following references: [AST-2017-013](http://downloads.digium.com/pub/security/AST-2017-013.html), [ASTERISK-27452](https://issues.asterisk.org/jira/browse/ASTERISK-27452), [CVE-2017-17090](https://security-tracker.debian.org/tracker/CVE-2017-17090).
What is the Common Weakness Enumeration (CWE) for CVE-2017-17090?
The Common Weakness Enumeration (CWE) for CVE-2017-17090 is CWE-459.