CVE-2023-37457
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
14/12/2023
Last modified:
29/12/2023
Description
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. A patch is available at commit a1ca0268254374b515fa5992f01340f7717113fa.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 18.20.0 (including) | |
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 19.0.0 (including) | 20.5.0 (including) |
| cpe:2.3:a:digium:asterisk:21.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc4:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert2:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert3:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:16.8.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



