CVE-2019-18976: Null Pointer Dereference
An issue was discovered in respjsipt38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18976?
CVE-2019-18976 is a vulnerability in Sangoma Asterisk and Certified Asterisk that allows for a NULL pointer dereference and crash.
How does CVE-2019-18976 affect Digium Asterisk?
Digium Asterisk versions between 13.0.0 and 13.29.1 are affected by CVE-2019-18976.
How does CVE-2019-18976 affect Digium Certified Asterisk?
Digium Certified Asterisk version 13.21, as well as its certified subversions (cert1, cert2, cert3, and cert4), are affected by CVE-2019-18976.
What is the severity of CVE-2019-18976?
CVE-2019-18976 has a severity score of 7.5 (High).
How can I fix CVE-2019-18976?
To fix CVE-2019-18976, it is recommended to update Sangoma Asterisk to versions beyond 13.x and Certified Asterisk to versions beyond 13.21-x.