Asterisk Project Security Advisory - AST-2018-009

Discussion in 'News Aggregator' started by Packet Storm, 21 Sep 2018.

  1. Packet Storm

    Packet Storm Guest

    Asterisk Project Security Advisory - There is a stack overflow vulnerability in the res_http_websocket.so module of Asterisk that allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket. The attacker's request causes Asterisk to run out of stack space and crash.

    Continue reading...
     

Share This Page

Loading...