5
CVSSv2

CVE-2017-9359

Published: 02/06/2017 Updated: 05/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x prior to 13.15.1 and 14.x prior to 14.4.1, Certified Asterisk 13.13 prior to 13.13-cert4, and other products, allows remote malicious users to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

digium open source 13.7.0

digium open source 13.10.0

digium open source 13.11.0

digium open source 13.15.0

digium open source 14.2.0

digium open source 13.2.0

digium open source 13.3.0

digium open source 13.5.0

digium open source 13.8.1

digium open source 13.8.2

digium open source 13.12.1

digium open source 13.12.2

digium open source 13.1.0

digium open source 13.6.0

digium open source 13.9.0

digium open source 13.13.0

digium open source 13.14.0

digium open source 13.8.0

digium open source 13.12.0

digium open source 13.0.0

digium open source 13.4.0

digium certified asterisk 13.13.0

Vendor Advisories

Two vulnerabilities were found in the PJSIP/PJProject communication library, which may result in denial of service For the oldstable distribution (jessie), these problems have been fixed in version 2100ast20130823-1+deb8u1 For the stable distribution (stretch), these problems had been fixed prior to the initial release We recommend that you ...