Asterisk Project Security Advisory - AST-2018-004

Discussion in 'News Aggregator' started by Packet Storm, 24 Feb 2018.

  1. Packet Storm

    Packet Storm Guest

    Asterisk Project Security Advisory - When processing a SUBSCRIBE request the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not limit the number of headers it processed despite having a fixed limit of 32. If more than 32 Accept headers were present the code would write outside of its memory and cause a crash.

    Continue reading...
     

Share This Page

Loading...