DEBIAN-CVE-2017-16671
Dashboard / Vulnerabilities / DEBIAN-CVE-2017-16671
Summary:
Details: A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and write past the end of the user field storage buffer. NOTE: this is different from CVE-2017-7617, which was only about the Party A buffer.
Affected packages
Package
Name: asterisk
Purl: pkg:deb/debian/asterisk?arch=source&distro=forky
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1:13.18.1~dfsg-1
Affected versions
0.1.11-3
0.1.11-3woody1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
