CVE-2020-35652: Medium severity asterisk vulnerability
An issue was discovered in respjsipdiversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message is received with a History-Info header that contains a tel-uri, or when a SIP 181 response is received that contains a tel-uri in the Diversion header.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35652.
What is the severity of CVE-2020-35652?
The severity of CVE-2020-35652 is medium (6.5).
What is the affected software?
The affected software is Digium Asterisk versions before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0.
What is the description of CVE-2020-35652?
CVE-2020-35652 is a vulnerability in Sangoma Asterisk that can cause a crash when a SIP message with a History-Info header containing a tel-uri is received, or when a SIP 181 response is received.
How can I fix CVE-2020-35652?
To fix CVE-2020-35652, it is recommended to upgrade to Sangoma Asterisk version 13.38.0, 16.15.0, 17.9.0, or 18.1.0 or later.