exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Asterisk Project Security Advisory - AST-2019-004

Asterisk Project Security Advisory - AST-2019-004
Posted Sep 5, 2019
Authored by Alexei Gradinari | Site asterisk.org

Asterisk Project Security Advisory - When Asterisk sends a re-invite initiating T.38 faxing, and the endpoint responds with a declined media stream a crash will then occur in Asterisk.

tags | advisory
advisories | CVE-2019-15297
SHA-256 | bb7ad078a0f3af2b1a5200e64d077cdaa043b5c90eed178634116a901bf0a64c

Asterisk Project Security Advisory - AST-2019-004

Change Mirror Download
               Asterisk Project Security Advisory - AST-2019-004

Product Asterisk
Summary Crash when negotiating for T.38 with a declined
stream
Nature of Advisory Remote Crash
Susceptibility Remote Authenticated Sessions
Severity Minor
Exploits Known No
Reported On August 05, 2019
Reported By Alexei Gradinari
Posted On September 05, 2019
Last Updated On September 4, 2019
Advisory Contact kharwell AT sangoma DOT com
CVE Name CVE-2019-15297

Description When Asterisk sends a re-invite initiating T.38
faxing, and the endpoint responds with a declined
media stream a crash will then occur in Asterisk.
Modules Affected res_pjsip_t38.c

Resolution If T.38 faxing is not required then setting the “t38_udptl”
configuration option on the endpoint to “no” disables this
functionality. This option defaults to “no” so you have to
have explicitly set it “yes” to potentially be affected by
this issue.

Otherwise, if T.38 faxing is required then Asterisk should
be upgraded to a fixed version.

Affected Versions
Product Release Series
Asterisk Open Source 15.x All releases
Asterisk Open Source 16.x All releases

Corrected In
Product Release
Asterisk Open Source 15.7.4,16.5.1

Patches
SVN URL Revision
http://downloads.asterisk.org/pub/security/AST-2019-004-15.diff Asterisk
15
http://downloads.asterisk.org/pub/security/AST-2019-004-16.diff Asterisk
16

Links https://issues.asterisk.org/jira/browse/ASTERISK-28495

Asterisk Project Security Advisories are posted at
http://www.asterisk.org/security

This document may be superseded by later versions; if so, the latest
version will be posted at
http://downloads.digium.com/pub/security/AST-2019-004.pdf and
http://downloads.digium.com/pub/security/AST-2019-004.html

Revision History
Date Editor Revisions Made
August 28, 2019 Kevin Harwell Initial revision

Asterisk Project Security Advisory - AST-2019-004
Copyright © 2019 Digium, Inc. All Rights Reserved.
Permission is hereby granted to distribute and publish this advisory in its
original, unaltered form.
Login or Register to add favorites

File Archive:

November 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    16 Files
  • 2
    Nov 2nd
    17 Files
  • 3
    Nov 3rd
    17 Files
  • 4
    Nov 4th
    11 Files
  • 5
    Nov 5th
    0 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    3 Files
  • 8
    Nov 8th
    59 Files
  • 9
    Nov 9th
    12 Files
  • 10
    Nov 10th
    6 Files
  • 11
    Nov 11th
    11 Files
  • 12
    Nov 12th
    1 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    9 Files
  • 15
    Nov 15th
    33 Files
  • 16
    Nov 16th
    53 Files
  • 17
    Nov 17th
    11 Files
  • 18
    Nov 18th
    14 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    26 Files
  • 22
    Nov 22nd
    22 Files
  • 23
    Nov 23rd
    10 Files
  • 24
    Nov 24th
    9 Files
  • 25
    Nov 25th
    11 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    20 Files
  • 29
    Nov 29th
    9 Files
  • 30
    Nov 30th
    21 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close