vulnerability
FreeBSD: VID-b330db5f-7225-11eb-8386-001999f8d30b (CVE-2020-35776): asterisk -- Remote crash in res_pjsip_diversion
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | Feb 18, 2021 | Dec 10, 2025 | Dec 10, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Feb 18, 2021
Added
Dec 10, 2025
Modified
Dec 10, 2025
Description
The Asterisk project reports: If a registered user is tricked into dialing a malicious number that sends lots of 181 responses to Asterisk, each one will cause a 181 to be sent back to the original caller with an increasing number of entries in the "Supported" header. Eventually the number of entries in the header exceeds the size of the entry array and causes a crash.
Solutions
freebsd-upgrade-package-asterisk13freebsd-upgrade-package-asterisk16freebsd-upgrade-package-asterisk18
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.