CVE-2019-15297

Name
CVE-2019-15297
Description
res_pjsip_t38 in Sangoma Asterisk 13.21-cert4, 15.7.3, and 16.5.0 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://downloads.asterisk.org/pub/security/AST-2019-004.html
Patch http://packetstormsecurity.com/files/154371/Asterisk-Project-Security-Advisory-AST-2019-004.html
FULLDISC http://seclists.org/fulldisclosure/2021/Mar/5
MISC http://packetstormsecurity.com/files/161671/Asterisk-Project-Security-Advisory-AST-2021-006.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 16.0.0 <= 16.5.0
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 15.0.0 <= 15.7.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status