vulnerability
FreeBSD: VID-be261737-c535-11e7-8da5-001999f8d30b (CVE-2017-16672): asterisk -- Memory/File Descriptor/RTP leak in pjsip session resource
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | Nov 9, 2017 | Dec 14, 2017 | Mar 25, 2026 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Nov 9, 2017
Added
Dec 14, 2017
Modified
Mar 25, 2026
Description
The Asterisk project reports: A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens the session object never gets destroyed. This then leads to file descriptors and RTP ports being leaked as well.
Solution
freebsd-upgrade-package-asterisk13
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.