CVE-2017-17664

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
13/12/2017
Last modified:
20/04/2025

Description

A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 13.0.0 (including) 13.18.4 (excluding)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 14.0.0 (including) 14.7.4 (excluding)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 15.0.0 (including) 15.1.4 (excluding)
cpe:2.3:a:digium:certified_asterisk:*:*:*:*:*:*:*:* 13.13 (including)
cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc4:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert5:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert6:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.13:cert7:*:*:*:*:*:*