Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29496
HistoryFeb 25, 2021 - 6:34 p.m.

Buffer Overflow

2021-02-2518:34:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
asterisk
buffer overflow
vulnerability
stack-based
res_rtp_asterisk.c
signedness comparison

EPSS

0.002

Percentile

52.5%

asterisk is vulnerable to buffer overflow. A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession. This is caused by a signedness comparison mismatch.

EPSS

0.002

Percentile

52.5%