First published: Thu Feb 18 2021(Updated: )
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Digium Asterisk | >=13.0.0<13.38.2 | |
Digium Asterisk | >=16.0.0<16.16.1 | |
Digium Asterisk | >=17.0.0<17.9.2 | |
Digium Asterisk | >=18.0<18.2.1 | |
Digium Certified Asterisk | =16.8 | |
Digium Certified Asterisk | =16.8-cert1-rc1 | |
Digium Certified Asterisk | =16.8-cert1-rc2 | |
Digium Certified Asterisk | =16.8-cert1-rc3 | |
Digium Certified Asterisk | =16.8-cert1-rc4 | |
Digium Certified Asterisk | =16.8-cert2 | |
Digium Certified Asterisk | =16.8-cert3 | |
Digium Certified Asterisk | =16.8-cert4 | |
Digium Certified Asterisk | =16.8-cert4-rc1 | |
Digium Certified Asterisk | =16.8-cert4-rc2 | |
Digium Certified Asterisk | =16.8-cert4-rc3 | |
Digium Certified Asterisk | =16.8-cert4-rc4 | |
Digium Certified Asterisk | =16.8-cert5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26906.
The severity of CVE-2021-26906 is medium with a score of 5.9.
Digium Asterisk versions through 13.38.1, 14.x through 16.16.0, 17.x through 17.9.1, and 18.x through 18.2.0, as well as Certified Asterisk through 16.8-cert5 are affected by CVE-2021-26906.
An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk.
Yes, please refer to the official Asterisk project security advisory AST-2021-005 and download the necessary patches or updates from the Asterisk downloads page.