CVE Vulnerabilities

CVE-2019-15297

NULL Pointer Dereference

Published: Sep 09, 2019 | Modified: Aug 30, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 15.0.0 (including) 15.7.3 (including)
Asterisk Digium 16.0.0 (including) 16.5.0 (including)
Asterisk Ubuntu bionic *
Asterisk Ubuntu disco *
Asterisk Ubuntu eoan *
Asterisk Ubuntu esm-apps/bionic *
Asterisk Ubuntu esm-apps/focal *
Asterisk Ubuntu esm-apps/xenial *
Asterisk Ubuntu focal *
Asterisk Ubuntu trusty *
Asterisk Ubuntu xenial *

Potential Mitigations

References