Versio.io

CVE-2019-13161

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 12-07-2019 10:15
Last modified: - 01-06-2022 09:58
Total changes: - 3

Description

An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chan_sip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
High
Attack complexity
Network
Attack vector
High
Availability
None
Confidentiality
None
Integrity
Low
Privileges required
Unchanged
Scope
None
User interaction
5.3
Base score
1.6
3.6
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert13 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=1.8.14.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.4.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert6
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert8 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert2 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=13.1.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.1.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=beta2
vendor=digium AND product=certified_asterisk AND version=1.8.10.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.6.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert6
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=1.8.8.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert5
vendor=digium AND product=certified_asterisk AND version=1.8.12.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.3.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=11.3.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert4 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=13.1.0
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert10
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=1.8.11.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.11.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1_rc3
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert9
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert15
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert7 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=beta5
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.4.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.5.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.13.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert1 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert1_rc2
vendor=digium AND product=certified_asterisk AND version=11.6.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=rc5
vendor=digium AND product=certified_asterisk AND version=1.8.1.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.4.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert8
vendor=digium AND product=certified_asterisk AND version=1.8.13.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert2 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.3.0
vendor=digium AND product=certified_asterisk AND version=11.5.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert1 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert1_rc2
vendor=digium AND product=certified_asterisk AND version=1.8.7.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.8.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.8.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=1.8.28.0 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.0.0
vendor=digium AND product=certified_asterisk AND version=11.0.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.4.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert14
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=beta4
vendor=digium AND product=certified_asterisk AND version=1.8.7.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.9.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert6
vendor=digium AND product=certified_asterisk AND version=11.4.0
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert12 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert1_rc3
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=rc4
vendor=digium AND product=certified_asterisk AND version=1.8.5.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.9.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.9.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.9.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.10.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert7
vendor=digium AND product=certified_asterisk AND version=1.8.13.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.14.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.28
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert1_rc1
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert10
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=11.6.0 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=13.1.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=beta1
vendor=digium AND product=certified_asterisk AND version=1.8.0.0 AND update=beta3
vendor=digium AND product=certified_asterisk AND version=1.8.4.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.6.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.6.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.7.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.8.0 AND update=rc5
vendor=digium AND product=certified_asterisk AND version=1.8.10.0 AND update=rc4
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=1.8.2.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.3.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.3.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1-rc3
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert5
vendor=digium AND product=certified_asterisk AND version=11.1.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert13
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert15 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert3 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert8
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert9
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=13.8.0
vendor=digium AND product=certified_asterisk AND version=1.8.8.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert
vendor=digium AND product=certified_asterisk AND version=1.8.11.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.12.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1_rc1
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1_rc2
vendor=digium AND product=certified_asterisk AND version=11.0.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=11.4.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=11.5.0
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert14 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert5 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert6 AND software_edition=lts
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert7
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert2_rc1
vendor=digium AND product=certified_asterisk AND version=1.8.1.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.2.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.3.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.4.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.6.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=1.8.10.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.10.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=1.8.11.0 AND update=-
vendor=digium AND product=certified_asterisk AND version=1.8.12.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.12.0 AND update=rc3
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=11.1.0
vendor=digium AND product=certified_asterisk AND version=11.1.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=11.3.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.5.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert11
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert16
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert5
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert1_rc1
vendor=digium AND product=certified_asterisk AND version=13.8.0 AND update=rc1
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert5-rc1
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert5-rc2
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert7
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=11.2 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=11.2 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=11.2 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=11.2 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert17
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert18
vendor=digium AND product=certified_asterisk AND version=11.6.0 AND update=rc2
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert1-rc3
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert1-rc3
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert1-rc4
vendor=digium AND product=certified_asterisk AND version=13.21 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=13.21 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert3-rc2
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert9-rc1
vendor=digium AND product=certified_asterisk AND version=13.21 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert12
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert14-rc2
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert1-rc3
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert7
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert5
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert7
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert1-rc3
vendor=digium AND product=certified_asterisk AND version=13.21 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=1.8.15 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert5
vendor=digium AND product=certified_asterisk AND version=11.6 AND update=cert14-rc1
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert3-rc1
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert5
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert2-rc1
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=13.8 AND update=cert4
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert9
vendor=digium AND product=certified_asterisk AND version=13.13-cert2
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert1
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=1.8.8.0 AND update=rc4
vendor=digium AND product=certified_asterisk AND version=1.8.11 AND update=cert3-rc1
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert2
vendor=digium AND product=certified_asterisk AND version=1.8.28 AND update=cert3
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert1-rc1
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert6
vendor=digium AND product=certified_asterisk AND version=13.1 AND update=cert8
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert6
vendor=digium AND product=certified_asterisk AND version=13.13 AND update=cert8
vendor=digium AND product=certified_asterisk AND version=13.18 AND update=cert1-rc2
vendor=digium AND product=certified_asterisk AND version=13.21 AND update=cert1
OR
vendor=digium AND product=asterisk AND versionStartIncluding=15.0.0 AND versionEndExcluding=15.7.3
vendor=digium AND product=asterisk AND versionStartIncluding=16.0.0 AND versionEndExcluding=16.4.1
vendor=digium AND product=asterisk AND versionStartIncluding=13.0.0 AND versionEndExcluding=13.27.1
OR
vendor=Debian AND product=debian_linux AND version=8.0
vendor=Debian AND product=debian_linux AND version=9.0
 

Reference

 


Keywords

NVD

 

CVE-2019-13161

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.