Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "13.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.5.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.10.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.10.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.12"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.14.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert2"
}
]
}