First published: Mon Apr 10 2017(Updated: )
Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asterisk | =13.0.0 | |
Asterisk | =13.0.0-beta1 | |
Asterisk | =13.0.0-beta2 | |
Asterisk | =13.0.0-beta3 | |
Asterisk | =13.0.1 | |
Asterisk | =13.0.2 | |
Asterisk | =13.1.0 | |
Asterisk | =13.1.0-rc1 | |
Asterisk | =13.1.0-rc2 | |
Asterisk | =13.1.1 | |
Asterisk | =13.2.0 | |
Asterisk | =13.2.0-rc1 | |
Asterisk | =13.2.1 | |
Asterisk | =13.3.0-rc1 | |
Asterisk | =13.3.2 | |
Asterisk | =13.4.0 | |
Asterisk | =13.4.0-rc1 | |
Asterisk | =13.5.0 | |
Asterisk | =13.5.0-rc1 | |
Asterisk | =13.6.0-rc1 | |
Asterisk | =13.7.0-rc1 | |
Asterisk | =13.7.0-rc2 | |
Asterisk | =13.7.1 | |
Asterisk | =13.7.2 | |
Asterisk | =13.8.0 | |
Asterisk | =13.8.0-rc1 | |
Asterisk | =13.8.1 | |
Asterisk | =13.8.2 | |
Asterisk | =13.9.0 | |
Asterisk | =13.9.1 | |
Asterisk | =13.10.0 | |
Asterisk | =13.10.0-rc1 | |
Asterisk | =13.11.0 | |
Asterisk | =13.11.1 | |
Asterisk | =13.11.2 | |
Asterisk | =13.12 | |
Asterisk | =13.12.0 | |
Asterisk | =13.12.1 | |
Asterisk | =13.12.2 | |
Asterisk | =13.13 | |
Asterisk | =13.13.0 | |
Asterisk | =13.14.0 | |
Asterisk | =14.0 | |
Asterisk | =14.0.0 | |
Asterisk | =14.0.0-beta1 | |
Asterisk | =14.0.0-beta2 | |
Asterisk | =14.0.0-rc1 | |
Asterisk | =14.0.0-rc2 | |
Asterisk | =14.0.1 | |
Asterisk | =14.0.2 | |
Asterisk | =14.1 | |
Asterisk | =14.01 | |
Asterisk | =14.1.0 | |
Asterisk | =14.1.1 | |
Asterisk | =14.1.2 | |
Asterisk | =14.02 | |
Asterisk | =14.2 | |
Asterisk | =14.2.0 | |
Asterisk | =14.2.1 | |
Asterisk | =14.3.0 | |
Asterisk Certified Asterisk | <=13.13-cert2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7617 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2017-7617, upgrade Asterisk to version 13.14.1 or 14.3.1 or later.
CVE-2017-7617 affects Asterisk Open Source 13.x versions prior to 13.14.1 and 14.x versions prior to 14.3.1.
CVE-2017-7617 is a buffer overflow vulnerability that can lead to remote code execution.
Yes, CVE-2017-7617 can be exploited remotely without requiring user interaction.