Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade asterisk | Jan 2, 2020 | Jul 12, 2019 |
| Debian | — | Upgrade asterisk | Jul 30, 2024 | Jul 12, 2019 |
| Freebsd | — | Upgrade asterisk13Upgrade asterisk16Upgrade asterisk15 | Jul 13, 2019 | Jul 12, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub