Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers to cause a denial of service (daemon crash) via TCP data using the (1) SIP, (2) HTTP, or (3) XMPP protocol.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade asterisk | Aug 30, 2017 | Jan 4, 2013 |
| Debian | — | Upgrade asterisk | Jul 30, 2024 | Jan 4, 2013 |
| Freebsd | — | Upgrade asterisk18Upgrade asterisk11Upgrade asterisk10 | Dec 10, 2025 | Jan 3, 2013 |
| Gentoo Linux | — | Upgrade net-misc/asterisk. | Oct 30, 2017 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub