CVE-2019-18976
22.11.2019, 17:15
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.Enginsight
Vendor | Product | Version |
---|---|---|
digium | asterisk | 13.0.0 ≤ 𝑥 ≤ 13.29.1 |
digium | certified_asterisk | 13.21 |
digium | certified_asterisk | 13.21:cert1 |
digium | certified_asterisk | 13.21:cert2 |
digium | certified_asterisk | 13.21:cert3 |
digium | certified_asterisk | 13.21:cert4 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References