CVE-2017-16672
MEDIUM
5,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM
4,3
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial
Description
AI Translation Available
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens the session object never gets destroyed. Eventually Asterisk can run out of memory and crash.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0527
Percentile
0,9th
Updated
EPSS Score Trend (Last 91 Days)
772
Missing Release of Resource after Effective Lifetime
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Other)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Cpu)
Applicable Platforms
Technologies:
Mobile
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert1_rc4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert1_rc1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Asterisk by Digium
Version Range Affected
From
14.0.0
(inclusive)
To
14.7.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Asterisk by Digium
Version Range Affected
From
15.0.0
(inclusive)
To
15.1.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Asterisk by Digium
Version Range Affected
From
13.0.0
(inclusive)
To
13.18.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert1_rc3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert6:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert1_rc2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Certified Asterisk by Digium
CPE Identifier
View Detailed Analysis
cpe:2.3:a:digium:certified_asterisk:13.13.0:cert1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://downloads.digium.com/pub/security/AST-2017-011.html
https://issues.asterisk.org/jira/browse/ASTERISK-27345
https://security.gentoo.org/glsa/201811-11
https://www.debian.org/security/2017/dsa-4076
http://www.securityfocus.com/bid/101765
http://downloads.digium.com/pub/security/AST-2017-011.html
https://issues.asterisk.org/jira/browse/ASTERISK-27345
https://security.gentoo.org/glsa/201811-11
https://www.debian.org/security/2017/dsa-4076
http://www.securityfocus.com/bid/101765