An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Digium | 13.0.0 (including) | 13.29.1 (including) |
Certified_asterisk | Digium | 13.21 (including) | 13.21 (including) |
Certified_asterisk | Digium | 13.21-cert1 (including) | 13.21-cert1 (including) |
Certified_asterisk | Digium | 13.21-cert2 (including) | 13.21-cert2 (including) |
Certified_asterisk | Digium | 13.21-cert3 (including) | 13.21-cert3 (including) |
Certified_asterisk | Digium | 13.21-cert4 (including) | 13.21-cert4 (including) |
Asterisk | Ubuntu | bionic | * |
Asterisk | Ubuntu | trusty | * |
Asterisk | Ubuntu | upstream | * |
Asterisk | Ubuntu | xenial | * |