Resource Management Errors Affecting asterisk package, versions [,1.8.11)[1.8.13.0,1.8.13.1)[10.5.0,10.5.2)[10.5.0,10.5.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.35% (87th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ASTERISK-2371566
  • published26 Jan 2022
  • disclosed9 Jul 2012
  • creditUnknown

Introduced: 9 Jul 2012

CVE-2012-3863  (opens in a new tab)
CWE-399  (opens in a new tab)

How to fix?

Upgrade asterisk to version 1.8.11, 1.8.13.1, 10.5.2, 10.5.2 or higher.

Overview

Affected versions of this package are vulnerable to Resource Management Errors channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Asterisk Business Edition C.3.x before C.3.7.5, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digiumphones does not properly handle a provisional response to a SIP reINVITE request, which allows remote authenticated users to cause a denial of service (RTP port exhaustion) via sessions that lack final responses.

CVSS Base Scores

version 3.1