First published: Fri Jun 02 2017(Updated: )
The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Digium Open Source | =13.0.0 | |
Digium Open Source | =13.1.0 | |
Digium Open Source | =13.1.0-rc1 | |
Digium Open Source | =13.1.0-rc2 | |
Digium Open Source | =13.2.0 | |
Digium Open Source | =13.2.0-rc1 | |
Digium Open Source | =13.3.0-rc1 | |
Digium Open Source | =13.4.0 | |
Digium Open Source | =13.4.0-rc1 | |
Digium Open Source | =13.5.0 | |
Digium Open Source | =13.5.0-rc1 | |
Digium Open Source | =13.6.0-rc1 | |
Digium Open Source | =13.7.0 | |
Digium Open Source | =13.7.0-rc1 | |
Digium Open Source | =13.8.0 | |
Digium Open Source | =13.8.0-rc1 | |
Digium Open Source | =13.8.1 | |
Digium Open Source | =13.8.2 | |
Digium Open Source | =13.9.0 | |
Digium Open Source | =13.9.0-rc1 | |
Digium Open Source | =13.10.0-rc1 | |
Digium Open Source | =13.11.0-rc1 | |
Digium Open Source | =13.12.0 | |
Digium Open Source | =13.12.0-rc1 | |
Digium Open Source | =13.12.1 | |
Digium Open Source | =13.12.2 | |
Digium Open Source | =13.13.0-rc1 | |
Digium Open Source | =13.14.0-rc1 | |
Digium Open Source | =13.15.0-rc1 | |
Digium Open Source | =14.2.0 | |
Digium Open Source | =14.2.0-rc1 | |
Digium Open Source | =14.2.0-rc2 | |
Digium Certified Asterisk | =13.13.0 | |
Digium Certified Asterisk | =13.13.0-cert1 | |
Digium Certified Asterisk | =13.13.0-cert1-rc1 | |
Digium Certified Asterisk | =13.13.0-cert1-rc2 | |
Digium Certified Asterisk | =13.13.0-cert1-rc3 | |
Digium Certified Asterisk | =13.13.0-cert1-rc4 | |
Digium Certified Asterisk | =13.13.0-cert2 | |
Digium Certified Asterisk | =13.13.0-cert3 | |
Digium Certified Asterisk | =13.13.0-rc1 | |
Digium Certified Asterisk | =13.13.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.