CVE-2018-7287: Medium severity Asterisk vulnerability
An issue was discovered in reshttpwebsocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/asteriskto a version that resolves this vulnerability.Fixed in 1:16.2.1~dfsg-1+deb10u2Fixed in 1:16.28.0~dfsg-0+deb10u3Fixed in 1:16.28.0~dfsg-0+deb11u3Fixed in 1:20.4.0~dfsg+~cs6.13.40431414-2 - Compensating control
Disable the HTTP server in Asterisk (WebSocket payload size 0 causes a busy loop when the HTTP server is enabled; default is disabled).
Event History
Frequently Asked Questions
What is CVE-2018-7287?
CVE-2018-7287 is a vulnerability in Asterisk 15.x through 15.2.1 that allows for mishandling of WebSocket payloads of size 0.
How severe is CVE-2018-7287?
CVE-2018-7287 has a severity rating of 5.9, which is considered medium.
What software is affected by CVE-2018-7287?
Asterisk versions 15.x through 15.2.1 are affected by CVE-2018-7287.
How can I fix CVE-2018-7287?
To fix CVE-2018-7287, upgrade to Asterisk version 1:16.2.1 or later.
Where can I find more information about CVE-2018-7287?
You can find more information about CVE-2018-7287 at the following references: [AST-2018-006](http://downloads.digium.com/pub/security/AST-2018-006.html), [SecurityFocus BID 103120](http://www.securityfocus.com/bid/103120), [SecurityTracker ID 1040419](http://www.securitytracker.com/id/1040419).