CVE-2019-15297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
09/09/2019
Last modified:
30/08/2022

Description

res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 15.0.0 (including) 15.7.3 (including)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 16.0.0 (including) 16.5.0 (including)