Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-99030
HistoryDec 18, 2023 - 12:00 a.m.

Asterisk Buffer Overflow Vulnerability (CNVD-2023-9903086)

2023-12-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
25
asterisk
buffer overflow
vulnerability
pjsip_header
linux
sip
iax
h323
exploit

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.6%

Asterisk is a software for PBX systems that runs on Linux and supports IP calls using SIP, IAX, and H323 protocols. Asterisk suffers from a buffer overflow vulnerability, which stems from the “update” function of the PJSIP_HEADER dialplan function that may exceed the available buffer space for storing the new value of the header, which can be exploited by an attacker to potentially overwrite memory or cause a crash.

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.6%