A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "13.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.5.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.9.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.10.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.14.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.15.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.4.0-rc1"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert1\\-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert1\\-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert1\\-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert1\\-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.13.0-cert3"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9358.json"