https://seclists.org/oss-sec/2023/q4/283: [ES2023-01] Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
Published Dec 15, 2023
·Updated
Affected Software
1 affected component
Asterisk Asterisk>20.1.0
Frequently Asked Questions
1
What is the severity of ES2023-01?
The severity of ES2023-01 is categorized as high due to the potential for Denial of Service attacks.
2
How do I fix ES2023-01?
To fix ES2023-01, upgrade Asterisk to one of the fixed versions: 18.20.1, 20.5.1, 21.0.1, or 18.9-cert6.
3
What type of attack does ES2023-01 allow?
ES2023-01 allows an attacker to perform a Denial of Service attack via DTLS Hello packets during call initiation.
4
Which versions of Asterisk are affected by ES2023-01?
Asterisk versions prior to 18.20.1, 20.5.1, 21.0.1, and 18.9-cert6 are affected by ES2023-01.
5
When was the vulnerability ES2023-01 published?
The vulnerability ES2023-01 was published on December 15, 2023.