vulnerability

FreeBSD: VID-b330db5f-7225-11eb-8386-001999f8d30b (CVE-2020-35776): asterisk -- Remote crash in res_pjsip_diversion

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Feb 18, 2021
Added
Dec 10, 2025
Modified
Dec 10, 2025

Description

The Asterisk project reports: If a registered user is tricked into dialing a malicious number that sends lots of 181 responses to Asterisk, each one will cause a 181 to be sent back to the original caller with an increasing number of entries in the "Supported" header. Eventually the number of entries in the header exceeds the size of the entry array and causes a crash.

Solutions

freebsd-upgrade-package-asterisk13freebsd-upgrade-package-asterisk16freebsd-upgrade-package-asterisk18
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.