Description
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume more and more memory since the transaction will never terminate (even if the call is hung up), ultimately leading to a restart or shutdown of Asterisk. Outbound authentication must be configured on the endpoint for this to occur.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2969-1 | asterisk security update |
EUVD |
EUVD-2020-20726 | An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume more and more memory since the transaction will never terminate (even if the call is hung up), ultimately leading to a restart or shutdown of Asterisk. Outbound authentication must be configured on the endpoint for this to occur. |
References
History
Thu, 15 Aug 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma
Sangoma asterisk |
|
| CPEs | cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Asterisk open Source
|
Sangoma
Sangoma asterisk |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:58.218Z
Reserved: 2020-11-06T00:00:00.000Z
Link: CVE-2020-28242
No data.
Status : Modified
Published: 2020-11-06T06:15:11.930
Modified: 2024-11-21T05:22:30.340
Link: CVE-2020-28242
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD