CVE-2019-12827
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
12/07/2019
Last modified:
21/07/2021
Description
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 13.0.0 (including) | 13.27.0 (excluding) |
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 15.0.0 (including) | 15.7.2 (excluding) |
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.4.0 (excluding) |
| cpe:2.3:a:digium:certified_asterisk:13.21:cert1:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:13.21:cert1-rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:13.21:cert1-rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:13.21:cert2:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:13.21:cert3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



