445
VMScore

CVE-2017-9358

Published: 02/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x prior to 13.15.1 and 14.x prior to 14.4.1 and Certified Asterisk 13.13 prior to 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).

Vulnerable Product Search on Vulmon Subscribe to Product

asterisk open source 13.12.0

asterisk open source 13.13.0

asterisk open source 13.8.1

asterisk open source 13.8.2

asterisk open source 13.4.0

asterisk open source 13.3.0

asterisk open source 13.11.0

asterisk open source 13.8.0

asterisk open source 13.2.0

asterisk open source 13.15.0

asterisk open source 13.14.0

asterisk open source 13.10.0

asterisk open source 13.9.0

asterisk open source 13.7.0

asterisk open source 13.6.0

asterisk open source 13.1.0

asterisk open source 13.12.1

asterisk open source 13.12.2

asterisk open source 13.5.0

asterisk open source 13.0.0

asterisk certified asterisk 13.13.0

asterisk open source 14.4.0

asterisk open source 14.0.0

asterisk open source 14.3.0

asterisk open source 14.2.1

asterisk open source 14.2.0

asterisk open source 14.1.0

Vendor Advisories

Debian Bug report logs - #863906 asterisk: CVE-2017-9358: AST-2017-004: Memory exhaustion on short SCCP packets Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Bernhard Schmidt <berni@debianorg> Date: Thu, 1 Jun 2017 19:39:04 UTC Se ...