Skip to main content

Tags Denial of Service

Asterisk Skinny: memory exhaustion denial of service

Published on May 23, 2017 in , ,

Description

Sending one malformed Skinny message to port 2000 will exhaust Asterisk’s memory resulting in a crash.

Impact

Abuse of this issue allows attackers to crash Asterisk when Skinny is exposed to attackers.

How to reproduce the issue

Start Asterisk and make sure the chan_skinny module is loaded. Then execute:

Read more about Asterisk Skinny: memory exhaustion denial of service

Asterisk PJSIP: out-of-bound memory access in multipart parser

Published on May 23, 2017 in , , ,

Description

A specially crafted SIP message with a malformed multipart body was found to cause a segmentation fault.

Impact

Abuse of this vulnerability leads to denial of service (DoS), and potentially remote code execution (RCE), in Asterisk when chan_pjsip is in use. This vulnerability is likely to affect other code that makes use of PJSIP.

Read more about Asterisk PJSIP: out-of-bound memory access in multipart parser