Asterisk Open Source Remote Buffer Overflow Vulnerability
BID:105934
Info
Asterisk Open Source Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 105934 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2018 12:00AM |
| Updated: | Nov 14 2018 12:00AM |
| Credit: | Jan Hoffmann |
| Vulnerable: |
Asterisk Open Source 15.6.1 Asterisk Open Source 15.1.4 Asterisk Open Source 15.1.3 Asterisk Open Source 15.1.1 Asterisk Open Source 15.1 Asterisk Open Source 16.0 Asterisk Open Source 15.1.2 |
| Not Vulnerable: |
Asterisk Open Source 16.0.1 Asterisk Open Source 15.6.2 |
Discussion
Asterisk Open Source Remote Buffer Overflow Vulnerability
Asterisk Open Source is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.
Following Asterisk products and versions are vulnerable:
Asterisk Open Source 15.x prior to 15.6.2
Asterisk Open Source 16.x prior to 16.0.1
Asterisk Open Source is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.
Following Asterisk products and versions are vulnerable:
Asterisk Open Source 15.x prior to 15.6.2
Asterisk Open Source 16.x prior to 16.0.1
Exploit / POC
Asterisk Open Source Remote Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Asterisk Open Source Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Asterisk Open Source Remote Buffer Overflow Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- AST-2018-010: Remote crash vulnerability DNS SRV and NAPTR lookups (Seclists)