CVE-2017-9359: High severity Asterisk vulnerability
The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9359?
CVE-2017-9359 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2017-9359?
To fix CVE-2017-9359, update to Asterisk versions 13.15.1 or 14.4.1 and above.
What types of systems are affected by CVE-2017-9359?
CVE-2017-9359 affects Asterisk Open Source versions 13.x before 13.15.1 and 14.x before 14.4.1, along with various certified Asterisk versions.
What kind of attacks can exploit CVE-2017-9359?
CVE-2017-9359 can be exploited by remote attackers sending crafted packets leading to an out-of-bounds read and application crash.
Is there a known exploit for CVE-2017-9359?
Yes, exploit techniques have been documented which can leverage the denial of service vulnerability in CVE-2017-9359.