Hide Forgot
A flaw was discovered in Asterisk 13.x, 14.x, 15.x and 13.18. By crafting an SDP message body with an invalid fmtp attribute Asterisk crashes when using the pjsip channel driver because pjproject's fmtp retrieval function fails to check if fmtp value is empty (set empty if previously parsed as invalid). References: http://downloads.asterisk.org/pub/security/AST-2018-003.html https://issues.asterisk.org/jira/browse/ASTERISK-27583 Patches: http://downloads.asterisk.org/pub/security/AST-2018-003-13.diff [Asterisk 13] http://downloads.asterisk.org/pub/security/AST-2018-003-14.diff [Asterisk 14] http://downloads.asterisk.org/pub/security/AST-2018-003-15.diff [Asterisk 15] http://downloads.asterisk.org/pub/security/AST-2018-003-13.18.diff [Certified Asterisk 13.18]
Created asterisk tracking bugs for this issue: Affects: epel-6 [bug 1548128] Affects: fedora-all [bug 1548127]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.