Rapid7

vulnerability

FreeBSD: VID-be261737-c535-11e7-8da5-001999f8d30b (CVE-2017-16672): asterisk -- Memory/File Descriptor/RTP leak in pjsip session resource

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Nov 9, 2017
Added
Dec 14, 2017
Modified
Mar 25, 2026

Description

The Asterisk project reports: A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens the session object never gets destroyed. This then leads to file descriptors and RTP ports being leaked as well.

Solution

freebsd-upgrade-package-asterisk13
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.