res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-6304 res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T00:42:03.821Z

Reserved: 2019-08-21T00:00:00

Link: CVE-2019-15297

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-09T21:15:10.827

Modified: 2024-11-21T04:28:24.290

Link: CVE-2019-15297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses