CVE-2020-35776: Buffer Overflow
A buffer overflow in respjsipdiversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35776?
CVE-2020-35776 is a buffer overflow vulnerability in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 that allows a remote attacker to crash Asterisk by misusing SIP 181 responses.
How does CVE-2020-35776 affect Digium Asterisk?
CVE-2020-35776 affects Digium Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1.
What is the severity of CVE-2020-35776?
CVE-2020-35776 has a severity rating of 6.5 (Medium).
How can an attacker exploit CVE-2020-35776?
An attacker can exploit CVE-2020-35776 by deliberately misusing SIP 181 responses to cause a buffer overflow and crash Asterisk.
Are there any fixes available for CVE-2020-35776?
Yes, you can find fixes for CVE-2020-35776 in the security advisory AST-2021-001 provided by the Asterisk Project.