CVE-2018-17281: High severity asterisk vulnerability
There is a stack consumption vulnerability in the reshttpwebsocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this stack consumption vulnerability?
The vulnerability ID for this stack consumption vulnerability is CVE-2018-17281.
Which Asterisk versions are affected by this vulnerability?
Asterisk versions through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0, as well as Certified Asterisk through 13.21-cert2, are affected by this vulnerability.
What is the severity rating of CVE-2018-17281?
The severity rating of CVE-2018-17281 is high with a CVSS score of 7.5.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a specially crafted HTTP request to upgrade the connection, causing Asterisk to crash.
Are there any known remediation steps for this vulnerability?
Yes, upgrading to Asterisk versions 13.23.1 or higher, 14.7.8 or higher, 15.6.1 or higher, or applying the necessary patches provided by the vendor can mitigate this vulnerability.