HomeDigiumCVE-2019-13161

CVE-2019-13161

MEDIUM
5.3CVSS
Published: 2019-07-12
Updated: 2024-11-21
AI Analysis

Description

An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chan_sip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
network
Complexity
high
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
high
Weaknesses
CWE-476

Metadata

Primary Vendor
DIGIUM
Published
7/12/2019
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

digium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : certified_asteriskdigium : asteriskdigium : asteriskdigium : asteriskdebian : debian_linuxdebian : debian_linux

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2019-13161 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com