CVE-2017-9372: Buffer Overflow
PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow and application crash) via a SIP packet with a crafted CSeq header in conjunction with a Via header that lacks a branch parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9372?
CVE-2017-9372 is rated as a critical severity vulnerability that allows for a denial of service due to a buffer overflow.
How do I fix CVE-2017-9372?
To fix CVE-2017-9372, update affected versions of PJSIP and Asterisk to versions 13.15.1, 14.4.1 or newer.
Which versions are affected by CVE-2017-9372?
CVE-2017-9372 affects Asterisk Open Source versions 13.x before 13.15.1 and 14.x before 14.4.1.
What type of attack does CVE-2017-9372 facilitate?
CVE-2017-9372 allows remote attackers to cause a denial of service by exploiting a crafted SIP packet.
Is CVE-2017-9372 exploitable from remote locations?
Yes, CVE-2017-9372 can be exploited by remote attackers without requiring physical access to the system.