Vulnerability Description
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | 13.0.0 |
Related Weaknesses (CWE)
References
- http://downloads.asterisk.org/pub/security/AST-2017-007.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/100583Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039253Third Party AdvisoryVDB Entry
- https://bugs.debian.org/873909Issue TrackingPatchThird Party Advisory
- https://issues.asterisk.org/jira/browse/ASTERISK-27152Issue TrackingVendor Advisory
- http://downloads.asterisk.org/pub/security/AST-2017-007.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/100583Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039253Third Party AdvisoryVDB Entry
- https://bugs.debian.org/873909Issue TrackingPatchThird Party Advisory
- https://issues.asterisk.org/jira/browse/ASTERISK-27152Issue TrackingVendor Advisory
FAQ
What is CVE-2017-14098?
CVE-2017-14098 is a vulnerability with a CVSS score of 7.5 (HIGH). In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
How severe is CVE-2017-14098?
CVE-2017-14098 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14098?
Check the references section above for vendor advisories and patch information. Affected products include: Digium Asterisk.