Asterisk Project Security Advisory - AST-2017-009

Discussion in 'News Aggregator' started by Packet Storm, 9 Nov 2017.

  1. Packet Storm

    Packet Storm Guest

    Asterisk Project Security Advisory - By carefully crafting invalid values in the Cseq and the Via header port, pjproject's packet parsing code can create strings larger than the buffer allocated to hold them. This will usually cause Asterisk to crash immediately. The packets do not have to be authenticated.

    Continue reading...
     

Share This Page

Loading...