In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-asterisk | Sep 26, 2017 | Sep 2, 2017 |
| Debian | debian-upgrade-asterisk | Jul 30, 2024 | Sep 2, 2017 | |
| Freebsd | freebsd-upgrade-package-asterisk13 | Sep 19, 2017 | Sep 1, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-asterisk | Oct 30, 2017 | Sep 2, 2017 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Sep 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub