CVE-2019-15297
Summary
| CVE | CVE-2019-15297 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-09 21:15:00 UTC |
| Updated | 2022-08-30 07:15:00 UTC |
| Description | res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference. |
Risk And Classification
Problem Types: CWE-476
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: AST-2021-006: Crash when negotiating T.38 with a zero port | FULLDISC | seclists.org | |
| AST-2019-004 | CONFIRM | downloads.asterisk.org | Patch, Vendor Advisory |
| Asterisk Project Security Advisory - AST-2019-004 ≈ Packet Storm | MISC | packetstormsecurity.com | Patch, Third Party Advisory, VDB Entry |
| Asterisk Project Security Advisory - AST-2021-006 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.