CVE-2017-17664

Published: Dic 13, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2017-8822 Aliases: GSD-2017-17664
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,9
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 4,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0128
Percentile
0,8th
Updated

EPSS Score Trend (Last 90 Days)

119

Improper Restriction of Operations within the Bounds of a Memory Buffer

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Memory Read Memory Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory)
Applicable Platforms
Languages: Assembly, C, C++, Memory-Unsafe
View CWE Details
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert8:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Asterisk by Digium

Version Range Affected
From 15.0.0 (inclusive)
To 15.1.4 (exclusive)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Asterisk by Digium

Version Range Affected
From 13.0.0 (inclusive)
To 13.18.4 (exclusive)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Asterisk by Digium

Version Range Affected
From 14.0.0 (inclusive)
To 14.7.4 (exclusive)
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert6:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert7:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

Version Range Affected
To 13.13 (inclusive)
cpe:2.3:a:digium:certified_asterisk:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Certified Asterisk by Digium

cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://downloads.digium.com/pub/security/AST-2017-012.html
https://issues.asterisk.org/jira/browse/ASTERISK-27382
https://issues.asterisk.org/jira/browse/ASTERISK-27429
https://www.debian.org/security/2017/dsa-4076
http://www.securityfocus.com/bid/102201
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/102201
http://www.securitytracker.com/id/1040009
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040009
http://downloads.digium.com/pub/security/AST-2017-012.html
https://issues.asterisk.org/jira/browse/ASTERISK-27382
https://issues.asterisk.org/jira/browse/ASTERISK-27429
https://www.debian.org/security/2017/dsa-4076
http://www.securityfocus.com/bid/102201
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/102201
http://www.securitytracker.com/id/1040009
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040009