← Back

CVE-2019-13161

nvd nist
Published: Jul 12, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.6 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chan_sip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).

Affected (217)

2 products
Certified Asterisk
Asterisk
1 product
Debian Linux
Configuration A
212 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 1.8.0.0
Version 1.8.0.0 beta1
Version 1.8.0.0 beta2
Version 1.8.0.0 beta3
Version 1.8.0.0 beta4
Version 1.8.0.0 beta5
Version 1.8.0.0 rc1
Version 1.8.0.0 rc2
Version 1.8.0.0 rc3
Version 1.8.0.0 rc4
Version 1.8.0.0 rc5
Version 1.8.1.0
Version 1.8.1.0 rc1
Version 1.8.10.0
Version 1.8.10.0 rc1
Version 1.8.10.0 rc2
Version 1.8.10.0 rc3
Version 1.8.10.0 rc4
Version 1.8.11.0
Version 1.8.11.0 rc1
Version 1.8.11.0 rc2
Version 1.8.11.0 rc3
Version 1.8.11 cert10
Version 1.8.11 cert1
Version 1.8.11 cert2
Version 1.8.11 cert3-rc1
Version 1.8.11 cert3-rc2
Version 1.8.11 cert3
Version 1.8.11 cert4
Version 1.8.11 cert5-rc1
Version 1.8.11 cert5-rc2
Version 1.8.11 cert5
Version 1.8.11 cert6
Version 1.8.11 cert7
Version 1.8.11 cert8
Version 1.8.11 cert9-rc1
Version 1.8.11 cert9
Version 1.8.11 cert
Version 1.8.12.0
Version 1.8.12.0 rc1
Version 1.8.12.0 rc2
Version 1.8.12.0 rc3
Version 1.8.13.0
Version 1.8.13.0 rc1
Version 1.8.13.0 rc2
Version 1.8.14.0 rc1
Version 1.8.14.0 rc2
Version 1.8.15
Version 1.8.15 cert1-rc1
Version 1.8.15 cert1-rc2
Version 1.8.15 cert1-rc3
Version 1.8.15 cert1
Version 1.8.15 cert1_rc1
Version 1.8.15 cert1_rc2
Version 1.8.15 cert1_rc3
Version 1.8.15 cert2
Version 1.8.15 cert3
Version 1.8.15 cert4
Version 1.8.15 cert5
Version 1.8.15 cert6
Version 1.8.15 cert7
Version 1.8.2.0
Version 1.8.2.0 rc1
Version 1.8.28.0
Version 1.8.28
Version 1.8.28 cert1-rc1
Version 1.8.28 cert1
Version 1.8.28 cert2
Version 1.8.28 cert2
Version 1.8.28 cert3
Version 1.8.28 cert4
Version 1.8.28 cert5
Version 1.8.3.0
Version 1.8.3.0 rc1
Version 1.8.3.0 rc2
Version 1.8.3.0 rc3
Version 1.8.4.0
Version 1.8.4.0 rc1
Version 1.8.4.0 rc2
Version 1.8.4.0 rc3
Version 1.8.5.0
Version 1.8.5.0 rc1
Version 1.8.6.0
Version 1.8.6.0 rc1
Version 1.8.6.0 rc2
Version 1.8.6.0 rc3
Version 1.8.7.0
Version 1.8.7.0 rc1
Version 1.8.7.0 rc2
Version 1.8.8.0
Version 1.8.8.0 rc1
Version 1.8.8.0 rc2
Version 1.8.8.0 rc3
Version 1.8.8.0 rc4
Version 1.8.8.0 rc5
Version 1.8.9.0
Version 1.8.9.0 rc1
Version 1.8.9.0 rc2
Version 1.8.9.0 rc3
Version 11.0.0
Version 11.0.0 rc1
Version 11.0.0 rc2
Version 11.1.0
Version 11.1.0 rc1
Version 11.1.0 rc2
Version 11.1.0 rc3
Version 11.2 cert1-rc2
Version 11.2 cert1
Version 11.2 cert2
Version 11.2 cert3
Version 11.3.0
Version 11.3.0 rc1
Version 11.3.0 rc2
Version 11.4.0
Version 11.4.0 rc1
Version 11.4.0 rc2
Version 11.4.0 rc3
Version 11.5.0
Version 11.5.0 rc1
Version 11.5.0 rc2
Version 11.6.0
Version 11.6.0
Version 11.6.0 rc1
Version 11.6.0 rc2
Version 11.6 cert1-rc1
Version 11.6 cert1-rc2
Version 11.6 cert10
Version 11.6 cert11
Version 11.6 cert12
Version 11.6 cert12
Version 11.6 cert13
Version 11.6 cert13
Version 11.6 cert14-rc1
Version 11.6 cert14-rc2
Version 11.6 cert14
Version 11.6 cert14
Version 11.6 cert15
Version 11.6 cert15
Version 11.6 cert16
Version 11.6 cert17
Version 11.6 cert18
Version 11.6 cert1
Version 11.6 cert1
Version 11.6 cert1_rc1
Version 11.6 cert1_rc2
Version 11.6 cert2
Version 11.6 cert2
Version 11.6 cert3
Version 11.6 cert3
Version 11.6 cert4
Version 11.6 cert4
Version 11.6 cert5
Version 11.6 cert5
Version 11.6 cert6
Version 11.6 cert6
Version 11.6 cert7
Version 11.6 cert7
Version 11.6 cert8
Version 11.6 cert8
Version 11.6 cert9
Version 13.1.0
Version 13.1.0 rc1
Version 13.1.0 rc2
Version 13.13-cert2
Version 13.13 cert1-rc1
Version 13.13 cert1-rc2
Version 13.13 cert1-rc3
Version 13.13 cert1-rc4
Version 13.13 cert2
Version 13.13 cert3
Version 13.13 cert4
Version 13.13 cert5
Version 13.13 cert6
Version 13.13 cert7
Version 13.13 cert8
Version 13.13 cert9
Version 13.18 cert1-rc1
Version 13.18 cert1-rc2
Version 13.18 cert1-rc3
Version 13.18 cert1
Version 13.18 cert2
Version 13.18 cert3
Version 13.18 cert4
Version 13.1 cert1-rc1
Version 13.1 cert1-rc3
Version 13.1 cert1
Version 13.1 cert2
Version 13.1 cert3-rc1
Version 13.1 cert3
Version 13.1 cert4
Version 13.1 cert5
Version 13.1 cert6
Version 13.1 cert7
Version 13.1 cert8
Version 13.21 cert1-rc1
Version 13.21 cert1-rc2
Version 13.21 cert1
Version 13.21 cert2
Version 13.21 cert3
Version 13.8.0
Version 13.8.0 rc1
Version 13.8 cert1-rc2
Version 13.8 cert1-rc3
Version 13.8 cert1
Version 13.8 cert1_rc1
Version 13.8 cert1_rc2
Version 13.8 cert1_rc3
Version 13.8 cert2-rc1
Version 13.8 cert2
Version 13.8 cert2_rc1
Version 13.8 cert3
Version 13.8 cert4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Digium
From 13.0.0 to 13.27.1
From 15.0.0 to 15.7.3
From 16.0.0 to 16.4.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0

References (8)

Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.