CVE-2018-17281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
24/09/2018
Last modified:
03/10/2019

Description

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digium:asterisk:*:*:*:*:lts:*:*:* 13.0.0 (including) 13.23.0 (including)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 14.0.0 (including) 14.7.7 (including)
cpe:2.3:a:digium:asterisk:*:*:*:*:standard:*:*:* 15.0.0 (including) 15.6.0 (including)
cpe:2.3:a:digium:certified_asterisk:11.6:cert12:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert13:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert14:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert15:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert16:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert17:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:11.6:cert18:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert3:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert4:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert5:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert6:*:*:lts:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.1:cert7:*:*:lts:*:*:*