CVE-2019-12827: Buffer Overflow
Published Jul 12, 2019
·Updated
Buffer overflow in respjsipmessaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
Affected Software
8 affected components
Asterisk>=13.0.0<13.27.0
Asterisk>=15.0.0<15.7.2
Asterisk>=16.0.0<16.4.0
Digium Asterisk Appliance Developer Kit=13.21-cert1
Digium Asterisk Appliance Developer Kit=13.21-cert1-rc1
Digium Asterisk Appliance Developer Kit=13.21-cert1-rc2
Digium Asterisk Appliance Developer Kit=13.21-cert2
Digium Asterisk Appliance Developer Kit=13.21-cert3
Event History
Jul 12, 2019
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12827?
CVE-2019-12827 is a buffer overflow vulnerability in the res_pjsip_messaging component of Digium Asterisk.
2
How can a remote user exploit CVE-2019-12827?
A remote authenticated user can exploit CVE-2019-12827 by sending a specially crafted SIP MESSAGE message.
3
Which versions of Digium Asterisk are affected by CVE-2019-12827?
Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier are affected by CVE-2019-12827.
4
What is the severity of CVE-2019-12827?
CVE-2019-12827 has a severity rating of 6.5 (medium).
5
How can I fix CVE-2019-12827?
To fix CVE-2019-12827, it is recommended to update to the latest version of Digium Asterisk.