CVE-2021-26906
Severity CVSS v4.0:
Pending analysis
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
18/02/2021
Last modified:
24/02/2021
Description
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 13.0.0 (including) | 13.38.2 (excluding) |
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.16.1 (excluding) |
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 17.0.0 (including) | 17.9.2 (excluding) |
| cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | 18.0 (including) | 18.2.1 (excluding) |
| cpe:2.3:a:digium:certified_asterisk:16.8:-:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert1-rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert1-rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert1-rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert1-rc4:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert2:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert3:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert4:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert4-rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert4-rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:digium:certified_asterisk:16.8:cert4-rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/161477/Asterisk-Project-Security-Advisory-AST-2021-005.html
- http://seclists.org/fulldisclosure/2021/Feb/61
- https://downloads.asterisk.org/pub/security/
- https://downloads.asterisk.org/pub/security/AST-2021-005.html
- https://issues.asterisk.org/jira/browse/ASTERISK-29196



