Asterisk Project Security Advisory - AST-2018-002

Discussion in 'News Aggregator' started by Packet Storm, 24 Feb 2018.

  1. Packet Storm

    Packet Storm Guest

    Asterisk Project Security Advisory - By crafting an SDP message with an invalid media format description Asterisk crashes when using the pjsip channel driver because pjproject's sdp parsing algorithm fails to catch the invalid media format description. The severity of this vulnerability is lessened since an endpoint must be authenticated prior to reaching the crash point, or it's configured with no authentication.

    Continue reading...
     

Share This Page

Loading...