CVE-2019-12827

Name
CVE-2019-12827
Description
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://issues.asterisk.org/jira/browse/ASTERISK-28447
Vendor Advisory http://downloads.digium.com/pub/security/AST-2019-002.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 16.0.0 < 16.4.0
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 13.0.0 < 13.27.0
cpe:2.3:a:digium:certified_asterisk:13.21:cert1-rc1:*:*:*:*:*:* certified_asterisk == None == 13.21
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 15.0.0 < 15.7.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status