CVE-2017-9358

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:asterisk:open_source:13.12.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.13.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.8.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.8.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.4.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.12.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.11.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.8.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.0.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.12.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.9.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.1.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.5.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.2.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.15.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.7.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.12.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.14.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:13.5.0:rc1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert1:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert1-rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert1-rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert1-rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert1-rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert2:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert3:*:*:*:*:*:*
cpe:2.3:a:asterisk:certified_asterisk:13.13.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:asterisk:open_source:14.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.0.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.2.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:14.1.0:rc1:*:*:*:*:*:*

Information

Published : 2017-06-01 22:29

Updated : 2019-10-02 17:03


NVD link : CVE-2017-9358

Mitre link : CVE-2017-9358


JSON object : View

CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Advertisement

dedicated server usa

Products Affected

asterisk

  • certified_asterisk
  • open_source