An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Digium | 14.0.0 (including) | 14.7.5 (including) |
Asterisk | Digium | 15.0.0 (including) | 15.2.1 (including) |
Asterisk | Digium | 13.19.1 (including) | 13.19.1 (including) |
Certified_asterisk | Digium | * | 13.18 (including) |
Asterisk | Ubuntu | artful | * |
Asterisk | Ubuntu | bionic | * |
Asterisk | Ubuntu | esm-apps/bionic | * |
Asterisk | Ubuntu | esm-apps/xenial | * |
Asterisk | Ubuntu | trusty | * |
Asterisk | Ubuntu | upstream | * |
Asterisk | Ubuntu | xenial | * |