CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
93.6%
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x
and Certified Asterisk through 13.21-x. If it receives a re-invite
initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL
pointer dereference and crash will occur. This is different from
CVE-2019-18940.
downloads.asterisk.org/pub/security/AST-2019-008.html
downloads.asterisk.org/pub/security/AST-2019-008.html
issues.asterisk.org/jira/browse/ASTERISK-28612
launchpad.net/bugs/cve/CVE-2019-18976
nvd.nist.gov/vuln/detail/CVE-2019-18976
packetstormsecurity.com/files/155436/Asterisk-Project-Security-Advisory-AST-2019-008.html
seclists.org/fulldisclosure/2019/Nov/20
security-tracker.debian.org/tracker/CVE-2019-18976
www.asterisk.org/downloads/security-advisories
www.cve.org/CVERecord?id=CVE-2019-18976
www.cybersecurity-help.cz/vdb/SB2019112218?affChecked=1
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
93.6%