CVE-2017-17664: Buffer Overflow
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17664.
What is the severity of CVE-2017-17664?
The severity of CVE-2017-17664 is medium with a CVSS score of 5.9.
What is the affected software?
The affected software includes Asterisk Open Source versions 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4, as well as Certified Asterisk before 13.13-cert9.
How does the vulnerability in Asterisk Open Source versions 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4, and Certified Asterisk before 13.13-cert9 cause a crash?
The vulnerability in Asterisk Open Source versions 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4, and Certified Asterisk before 13.13-cert9 can cause a crash when certain compound RTCP packets are received, which triggers a crash in the RTCP Stack.
How can I fix the vulnerability in Asterisk Open Source versions 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4, and Certified Asterisk before 13.13-cert9?
To fix the vulnerability, update to Asterisk Open Source versions 13.18.4, 14.7.4, or 15.1.4, or upgrade to Certified Asterisk 13.13-cert9 or later.