CVE-2019-18976
Summary
| CVE | CVE-2019-18976 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-22 17:15:00 UTC |
| Updated | 2022-06-03 14:41:00 UTC |
| Description | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| downloads.asterisk.org/pub/security/AST-2019-008.html |
CONFIRM |
downloads.asterisk.org |
Vendor Advisory |
| Full Disclosure: AST-2019-008: Re-invite with T.38 and malformed SDP causes crash. |
MISC |
seclists.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2969-1] asterisk security update |
MLIST |
lists.debian.org |
|
| Multiple vulnerabilities in Digium Asterisk and Certified Asterisk |
MISC |
www.cybersecurity-help.cz |
Third Party Advisory |
| Asterisk Project Security Advisory - AST-2019-008 ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Third Party Advisory, VDB Entry |
| Security Advisories | Asterisk.org |
MISC |
www.asterisk.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179170 Debian Security Update for asterisk (DLA 2969-1)