Total vulnerabilities in the database
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.
Software | From | Fixed in |
---|---|---|
digium / certified_asterisk | 13.21-cert1 | 13.21-cert1.x |
digium / certified_asterisk | 13.21-cert2 | 13.21-cert2.x |
digium / certified_asterisk | 13.21-cert3 | 13.21-cert3.x |
digium / certified_asterisk | 13.21 | 13.21.x |
digium / certified_asterisk | 13.21-cert4 | 13.21-cert4.x |
digium / asterisk | 13.0.0 | 13.29.1.x |
debian / debian_linux | 9.0 | 9.0.x |