CVE-2017-17090

Source
https://cve.org/CVERecord?id=CVE-2017-17090
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17090.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-17090
Downstream
Published
2017-12-02T00:29:00.247Z
Modified
2026-02-13T08:11:36.390515Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in chanskinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chanskinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.

References

Affected packages

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

13.*
13.13.0
13.13.0-rc1
13.13.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17090.json"