CVE-2019-12827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
12/07/2019
Last modified:
21/07/2021

Description

Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 13.0.0 (including) 13.27.0 (excluding)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 15.0.0 (including) 15.7.2 (excluding)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 16.0.0 (including) 16.4.0 (excluding)
cpe:2.3:a:digium:certified_asterisk:13.21:cert1:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.21:cert1-rc1:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.21:cert1-rc2:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.21:cert2:*:*:*:*:*:*
cpe:2.3:a:digium:certified_asterisk:13.21:cert3:*:*:*:*:*:*