CVE-2018-7287
22.02.2018, 00:29
An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).Enginsight
| Vendor | Product | Version |
|---|---|---|
| digium | asterisk | 15.0.0:beta1 |
| digium | asterisk | 15.0.0:rc1 |
| digium | asterisk | 15.1.0 |
| digium | asterisk | 15.1.0:rc1 |
| digium | asterisk | 15.1.0:rc2 |
| digium | asterisk | 15.1.1 |
| digium | asterisk | 15.1.2 |
| digium | asterisk | 15.1.3 |
| digium | asterisk | 15.1.4 |
| digium | asterisk | 15.1.5 |
| digium | asterisk | 15.2.0 |
| digium | asterisk | 15.2.0:rc1 |
| digium | asterisk | 15.2.0:rc2 |
| digium | asterisk | 15.2.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References