An issue was discovered in chan_skinny.c in Asterisk Open Source...
Vulnerability Description
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-17090
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securitytracker.com/id/1039948
- https://www.exploit-db.com/exploits/43992/
- http://www.securityfocus.com/bid/102023
- https://issues.asterisk.org/jira/browse/ASTERISK-27452
- https://lists.debian.org/debian-lts-announce/2017/12/msg00028.html
- https://www.debian.org/security/2017/dsa-4076
- http://downloads.digium.com/pub/security/AST-2017-013.html
More from digium
View All →Affected Vendor
digium
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.