6.5
CVSSv3

CVE-2019-7251

Published: 28/03/2019 Updated: 01/04/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and previous versions and 16.1.1 and previous versions allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk

Vendor Advisories

Debian Bug report logs - #923690 asterisk: CVE-2019-7251: Remote crash vulnerability with SDP protocol violation Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 3 Mar 2019 21:15:02 U ...

Mailing Lists

Asterisk Project Security Advisory - AST-2019-001 Product Asterisk Summary Remote crash vulnerability with SDP protocol violation Nature of Advisory Denial Of Service ...