CVE-2019-15297: Null Pointer Dereference
respjsipt38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-15297?
CVE-2019-15297 is a vulnerability in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 that allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk.
What is the severity of CVE-2019-15297?
The severity of CVE-2019-15297 is medium with a CVSS score of 6.5.
How does CVE-2019-15297 affect Sangoma Asterisk?
CVE-2019-15297 affects Sangoma Asterisk versions 15.x before 15.7.4 and 16.x before 16.5.1.
How can I fix CVE-2019-15297?
To fix CVE-2019-15297, update Sangoma Asterisk to version 15.7.4 or 16.5.1 (or later if available).
Where can I find more information about CVE-2019-15297?
You can find more information about CVE-2019-15297 at the following references: [AST-2019-004](https://downloads.asterisk.org/pub/security/AST-2019-004.html), [ASTERISK-28495](https://issues.asterisk.org/jira/browse/ASTERISK-28495), [CVE-2019-15297](https://security-tracker.debian.org/tracker/CVE-2019-15297).