The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_source | Digium | 13.0.0 (including) | 13.0.0 (including) |
Open_source | Digium | 13.1.0 (including) | 13.1.0 (including) |
Open_source | Digium | 13.1.0-rc1 (including) | 13.1.0-rc1 (including) |
Open_source | Digium | 13.1.0-rc2 (including) | 13.1.0-rc2 (including) |
Open_source | Digium | 13.2.0 (including) | 13.2.0 (including) |
Open_source | Digium | 13.2.0-rc1 (including) | 13.2.0-rc1 (including) |
Open_source | Digium | 13.3.0-rc1 (including) | 13.3.0-rc1 (including) |
Open_source | Digium | 13.4.0 (including) | 13.4.0 (including) |
Open_source | Digium | 13.4.0-rc1 (including) | 13.4.0-rc1 (including) |
Open_source | Digium | 13.5.0 (including) | 13.5.0 (including) |
Open_source | Digium | 13.5.0-rc1 (including) | 13.5.0-rc1 (including) |
Open_source | Digium | 13.6.0-rc1 (including) | 13.6.0-rc1 (including) |
Open_source | Digium | 13.7.0 (including) | 13.7.0 (including) |
Open_source | Digium | 13.7.0-rc1 (including) | 13.7.0-rc1 (including) |
Open_source | Digium | 13.8.0 (including) | 13.8.0 (including) |
Open_source | Digium | 13.8.0-rc1 (including) | 13.8.0-rc1 (including) |
Open_source | Digium | 13.8.1 (including) | 13.8.1 (including) |
Open_source | Digium | 13.8.2 (including) | 13.8.2 (including) |
Open_source | Digium | 13.9.0 (including) | 13.9.0 (including) |
Open_source | Digium | 13.9.0-rc1 (including) | 13.9.0-rc1 (including) |
Open_source | Digium | 13.10.0-rc1 (including) | 13.10.0-rc1 (including) |
Open_source | Digium | 13.11.0-rc1 (including) | 13.11.0-rc1 (including) |
Open_source | Digium | 13.12.0 (including) | 13.12.0 (including) |
Open_source | Digium | 13.12.0-rc1 (including) | 13.12.0-rc1 (including) |
Open_source | Digium | 13.12.1 (including) | 13.12.1 (including) |
Open_source | Digium | 13.12.2 (including) | 13.12.2 (including) |
Open_source | Digium | 13.13.0-rc1 (including) | 13.13.0-rc1 (including) |
Open_source | Digium | 13.14.0-rc1 (including) | 13.14.0-rc1 (including) |
Open_source | Digium | 13.15.0-rc1 (including) | 13.15.0-rc1 (including) |
Open_source | Digium | 14.2.0 (including) | 14.2.0 (including) |
Open_source | Digium | 14.2.0-rc1 (including) | 14.2.0-rc1 (including) |
Open_source | Digium | 14.2.0-rc2 (including) | 14.2.0-rc2 (including) |
Pjproject | Ubuntu | trusty | * |
Pjproject | Ubuntu | upstream | * |
Pjproject | Ubuntu | xenial | * |
Pjproject | Ubuntu | yakkety | * |
Pjproject | Ubuntu | zesty | * |