CVE-2020-35776

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
18/02/2021
Last modified:
24/02/2021

Description

A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 13.0.0 (including) 13.38.1 (including)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 16.0.0 (including) 16.15.1 (including)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 17.0.0 (including) 17.9.1 (including)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* 18.0 (including) 18.1.1 (including)