what you don't know can hurt you

Asterisk Project Security Advisory - AST-2019-004

Asterisk Project Security Advisory - AST-2019-004
Posted Sep 5, 2019
Authored by Alexei Gradinari | Site asterisk.org

Asterisk Project Security Advisory - When Asterisk sends a re-invite initiating T.38 faxing, and the endpoint responds with a declined media stream a crash will then occur in Asterisk.

tags | advisory
advisories | CVE-2019-15297
MD5 | ebb905d4bf32313165ee3f35bdfdaef5

Asterisk Project Security Advisory - AST-2019-004

Change Mirror Download
               Asterisk Project Security Advisory - AST-2019-004

Product Asterisk
Summary Crash when negotiating for T.38 with a declined
stream
Nature of Advisory Remote Crash
Susceptibility Remote Authenticated Sessions
Severity Minor
Exploits Known No
Reported On August 05, 2019
Reported By Alexei Gradinari
Posted On September 05, 2019
Last Updated On September 4, 2019
Advisory Contact kharwell AT sangoma DOT com
CVE Name CVE-2019-15297

Description When Asterisk sends a re-invite initiating T.38
faxing, and the endpoint responds with a declined
media stream a crash will then occur in Asterisk.
Modules Affected res_pjsip_t38.c

Resolution If T.38 faxing is not required then setting the “t38_udptl”
configuration option on the endpoint to “no” disables this
functionality. This option defaults to “no” so you have to
have explicitly set it “yes” to potentially be affected by
this issue.

Otherwise, if T.38 faxing is required then Asterisk should
be upgraded to a fixed version.

Affected Versions
Product Release Series
Asterisk Open Source 15.x All releases
Asterisk Open Source 16.x All releases

Corrected In
Product Release
Asterisk Open Source 15.7.4,16.5.1

Patches
SVN URL Revision
http://downloads.asterisk.org/pub/security/AST-2019-004-15.diff Asterisk
15
http://downloads.asterisk.org/pub/security/AST-2019-004-16.diff Asterisk
16

Links https://issues.asterisk.org/jira/browse/ASTERISK-28495

Asterisk Project Security Advisories are posted at
http://www.asterisk.org/security

This document may be superseded by later versions; if so, the latest
version will be posted at
http://downloads.digium.com/pub/security/AST-2019-004.pdf and
http://downloads.digium.com/pub/security/AST-2019-004.html

Revision History
Date Editor Revisions Made
August 28, 2019 Kevin Harwell Initial revision

Asterisk Project Security Advisory - AST-2019-004
Copyright © 2019 Digium, Inc. All Rights Reserved.
Permission is hereby granted to distribute and publish this advisory in its
original, unaltered form.
Login or Register to add favorites

File Archive:

May 2021

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    1 Files
  • 2
    May 2nd
    4 Files
  • 3
    May 3rd
    27 Files
  • 4
    May 4th
    17 Files
  • 5
    May 5th
    3 Files
  • 6
    May 6th
    32 Files
  • 7
    May 7th
    11 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close