Vulnerability Database

299,184

Total vulnerabilities in the database

CVE-2024-42491

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with .1 or [.1], and res_resolver_unbound is loaded, Asterisk will crash with a SEGV. To receive a patch, users should upgrade to one of the following versions: 18.24.3, 20.9.3, 21.4.3, certified-18.9-cert12, certified-20.7-cert2. Two workarounds are available. Disable res_resolver_unbound by setting noload = res_resolver_unbound.so in modules.conf, or set rewrite_contact = yes on all PJSIP endpoints. NOTE: This may not be appropriate for all Asterisk configurations.

  • Published: Sep 5, 2024
  • Updated: Nov 4, 2025
  • CVE: CVE-2024-42491
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.7
  • AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Software From Fixed in
sangoma / asterisk - 18.24.3
sangoma / asterisk 20.0.0 20.9.3
sangoma / asterisk 21.0.0 21.4.3.x
sangoma / certified_asterisk - 18.9
sangoma / certified_asterisk 18.9 18.9.x
sangoma / certified_asterisk 18.9-cert1 18.9-cert1.x
sangoma / certified_asterisk 18.9-cert1-rc1 18.9-cert1-rc1.x
sangoma / certified_asterisk 18.9-cert10 18.9-cert10.x
sangoma / certified_asterisk 18.9-cert11 18.9-cert11.x
sangoma / certified_asterisk 18.9-cert2 18.9-cert2.x
sangoma / certified_asterisk 18.9-cert3 18.9-cert3.x
sangoma / certified_asterisk 18.9-cert4 18.9-cert4.x
sangoma / certified_asterisk 18.9-cert5 18.9-cert5.x
sangoma / certified_asterisk 18.9-cert6 18.9-cert6.x
sangoma / certified_asterisk 18.9-cert7 18.9-cert7.x
sangoma / certified_asterisk 18.9-cert8 18.9-cert8.x
sangoma / certified_asterisk 18.9-cert8-rc1 18.9-cert8-rc1.x
sangoma / certified_asterisk 18.9-cert8-rc2 18.9-cert8-rc2.x
sangoma / certified_asterisk 18.9-cert9 18.9-cert9.x
sangoma / certified_asterisk 20.7-cert1 20.7-cert1.x
sangoma / certified_asterisk 20.7-cert1-rc1 20.7-cert1-rc1.x
sangoma / certified_asterisk 20.7-cert1-rc2 20.7-cert1-rc2.x
sangoma / certified_asterisk 20.7-cert2 20.7-cert2.x