CVE-2019-13161 - CVE House
Back to Database
Status published Medium CVE-2019-13161

An issue was discovered in Asterisk Open Source through 13.27.0,...

Vulnerability Description

An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chan_sip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13161

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

certified asterisk, asterisk, debian linux
Vulnerable Versions:
1.8.0.0, 1.8.1.0, 1.8.2.0, 1.8.3.0, 1.8.4.0, 1.8.5.0, 1.8.6.0, 1.8.7.0, 1.8.8.0, 1.8.9.0, 1.8.10.0, 1.8.11, 1.8.11.0, 1.8.12.0, 1.8.13.0, 1.8.14.0, 1.8.15, 1.8.28, 1.8.28.0, 11.0.0, 11.1.0, 11.2, 11.3.0, 11.4.0, 11.5.0, 11.6, 11.6.0, 13.1, 13.1.0, 13.8, 13.8.0, 13.13, 13.13-cert2, 13.18, 13.21, 13.0.0, 15.0.0, 16.0.0, 8.0, 9.0

Timeline

Official Publish: July 12th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.