CVE-2017-9358: High severity Sangoma Asterisk vulnerability
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9358?
The severity of CVE-2017-9358 is classified as high due to its potential for causing memory exhaustion leading to service disruptions.
How do I fix CVE-2017-9358?
To fix CVE-2017-9358, upgrade to Asterisk version 13.15.1, 14.4.1, or any later version of the software.
What software versions are affected by CVE-2017-9358?
CVE-2017-9358 affects Asterisk Open Source versions 13.x prior to 13.15.1 and 14.x prior to 14.4.1.
What kind of attack can exploit CVE-2017-9358?
An attacker can exploit CVE-2017-9358 by sending specially crafted SCCP packets that trigger an infinite loop, resulting in memory exhaustion.
Is CVE-2017-9358 present in certified Asterisk versions?
Yes, CVE-2017-9358 is present in Certified Asterisk version 13.13 prior to 13.13-cert4.