res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Digium | 15.0.0 (including) | 15.7.3 (including) |
Asterisk | Digium | 16.0.0 (including) | 16.5.0 (including) |
Asterisk | Ubuntu | bionic | * |
Asterisk | Ubuntu | disco | * |
Asterisk | Ubuntu | eoan | * |
Asterisk | Ubuntu | esm-apps/bionic | * |
Asterisk | Ubuntu | esm-apps/focal | * |
Asterisk | Ubuntu | esm-apps/xenial | * |
Asterisk | Ubuntu | focal | * |
Asterisk | Ubuntu | trusty | * |
Asterisk | Ubuntu | xenial | * |