Vulnerability Description
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | >= 13.0.0, < 13.27.0 |
| Digium | Certified Asterisk | 13.21 |
Related Weaknesses (CWE)
References
- http://downloads.digium.com/pub/security/AST-2019-002.htmlVendor Advisory
- https://issues.asterisk.org/jira/browse/ASTERISK-28447Vendor Advisory
- http://downloads.digium.com/pub/security/AST-2019-002.htmlVendor Advisory
- https://issues.asterisk.org/jira/browse/ASTERISK-28447Vendor Advisory
FAQ
What is CVE-2019-12827?
CVE-2019-12827 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted S...
How severe is CVE-2019-12827?
CVE-2019-12827 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12827?
Check the references section above for vendor advisories and patch information. Affected products include: Digium Asterisk, Digium Certified Asterisk.