https://seclists.org/oss-sec/2024/q2/250: asterisk security leases 18.23.1, 20.8.1, & 21.3.1
Published May 21, 2024
·Updated
Affected Software
1 affected component
Asterisk Asterisk
The vulnerability GHSA-qqxj-v78h-hrf9 has been classified as a security issue allowing unauthorized SIP request handling.
To fix GHSA-qqxj-v78h-hrf9, upgrade to Asterisk versions 18.23.1, 20.8.1, or 21.3.1 which contain the necessary security patches.
GHSA-qqxj-v78h-hrf9 affects systems running Asterisk prior to versions 18.23.1, 20.8.1, and 21.3.1.
GHSA-qqxj-v78h-hrf9 exploits incorrect matching of unauthorized SIP requests as endpoints in the Asterisk server.
Yes, GHSA-qqxj-v78h-hrf9 can lead to unauthorized access and manipulation of SIP requests on the Asterisk server.