← Back

CVE-2018-17281

nvd nist
Published: Sep 24, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.

Affected (33)

2 products
Asterisk
Certified Asterisk
1 product
Debian Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Digium
From 14.0.0 to 14.7.7
From 13.0.0 to 13.23.0
From 15.0.0 to 15.6.0
Configuration B
28 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 11.6 cert12
Version 11.6 cert13
Version 11.6 cert14
Version 11.6 cert15
Version 11.6 cert16
Version 11.6 cert17
Version 11.6 cert18
Version 13.13 cert1
Version 13.13 cert2
Version 13.13 cert3
Version 13.13 cert4
Version 13.13 cert5
Version 13.13 cert6
Version 13.13 cert7
Version 13.13 cert8
Version 13.13 cert9
Version 13.1 cert3
Version 13.1 cert4
Version 13.1 cert5
Version 13.1 cert6
Version 13.1 cert7
Version 13.1 cert8
Version 13.21 cert1
Version 13.21 cert2
Version 13.8 cert1
Version 13.8 cert2
Version 13.8 cert3
Version 13.8 cert4
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0

References (20)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.