First published: Sat Dec 02 2017(Updated: )
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Digium Certified Asterisk | <=13.13 | |
Digium Certified Asterisk | =13.13-cert1 | |
Digium Certified Asterisk | =13.13-cert1_rc1 | |
Digium Certified Asterisk | =13.13-cert1_rc2 | |
Digium Certified Asterisk | =13.13-cert1_rc3 | |
Digium Certified Asterisk | =13.13-cert1_rc4 | |
Digium Certified Asterisk | =13.13-cert2 | |
Digium Certified Asterisk | =13.13-cert3 | |
Digium Certified Asterisk | =13.13-cert4 | |
Digium Certified Asterisk | =13.13-cert5 | |
Digium Certified Asterisk | =13.13-cert6 | |
Digium Certified Asterisk | =13.13-cert7 | |
Digium Asterisk | <=13.8.2 | |
Digium Asterisk | <=14.7.2 | |
Digium Asterisk | <=15.1.2 | |
debian/asterisk | 1:16.2.1~dfsg-1+deb10u2 1:16.28.0~dfsg-0+deb10u3 1:16.28.0~dfsg-0+deb11u3 1:20.4.0~dfsg+~cs6.13.40431414-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17090 is high.
CVE-2017-17090 affects Asterisk Open Source versions 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older.
The remedy for CVE-2017-17090 is to update Asterisk Open Source to version 13.13-cert7 and older, or 1:16.2.1~dfsg-1+deb10u2, 1:16.28.0~dfsg-0+deb10u3, 1:16.28.0~dfsg-0+deb11u3, 1:20.4.0~dfsg+~cs6.13.40431414-2 or newer.
You can find more information about CVE-2017-17090 at the following references: [AST-2017-013](http://downloads.digium.com/pub/security/AST-2017-013.html), [ASTERISK-27452](https://issues.asterisk.org/jira/browse/ASTERISK-27452), [CVE-2017-17090](https://security-tracker.debian.org/tracker/CVE-2017-17090).
The Common Weakness Enumeration (CWE) for CVE-2017-17090 is CWE-459.