5
CVSSv2

CVE-2021-32558

Published: 30/07/2021 Updated: 28/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Sangoma Asterisk 13.x prior to 13.38.3, 16.x prior to 16.19.1, 17.x prior to 17.9.4, and 18.x prior to 18.5.1, and Certified Asterisk prior to 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk

digium certified asterisk 16.8

debian debian linux 9.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #991931 CVE-2021-32686 / AST-2021-009: pjproject/pjsip: crash when SSL socket destroyed during handshake Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Bernhard Schmidt <berni@debianorg> Date: Fri, 6 Aug 202 ...
Debian Bug report logs - #991710 asterisk: CVE-2021-32558 Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 30 Jul 2021 15:03:02 UTC Severity: important Tags: security, upstream Found ...
Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service For the stable distribution (bullseye), these problems have been fixed in version 1:16161~dfsg-1+deb11u1 We recommend that you upgrade your asterisk packages For the detailed security status of asterisk ple ...