CVE Vulnerabilities

CVE-2019-15297

NULL Pointer Dereference

Published: Sep 09, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 15.0.0 (including) 15.7.3 (including)
Asterisk Digium 16.0.0 (including) 16.5.0 (including)
Asterisk Ubuntu bionic *
Asterisk Ubuntu disco *
Asterisk Ubuntu eoan *
Asterisk Ubuntu esm-apps/bionic *
Asterisk Ubuntu esm-apps/focal *
Asterisk Ubuntu esm-apps/xenial *
Asterisk Ubuntu focal *
Asterisk Ubuntu trusty *
Asterisk Ubuntu xenial *

Potential Mitigations

References