An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chansip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chansip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.8.5.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.7.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.7.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.7.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8.0-rc4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8.0-rc5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10.0-rc4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert10"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert3\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert3\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert5\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert5\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert8"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert9"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert9\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.13.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.13.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.13.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.14.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.14.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1\\-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1_rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert1_rc3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.28.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "11.2-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "11.2-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.2-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "11.2-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "11.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.3.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.4.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.4.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "11.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.5.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.5.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1_rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert10"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert11"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert12"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert12"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert13"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert13"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert15"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert15"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert16"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert17"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert18"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert8"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert8"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert9"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert1\\-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert3\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "13.1-cert8"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert1\\-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert1_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert1_rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert1_rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert2\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert2_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "13.8-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1\\-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1\\-rc4"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert8"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert9"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert1\\-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "13.18-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "13.21-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "13.21-cert1\\-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.21-cert1\\-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.21-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.21-cert3"
},
{
"introduced": "13.0.0"
},
{
"fixed": "13.27.1"
},
{
"introduced": "15.0.0"
},
{
"fixed": "15.7.3"
},
{
"introduced": "16.0.0"
},
{
"fixed": "16.4.1"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13161.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-beta3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-beta4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-beta5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0.0-rc5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.1.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.1.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.2.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.2.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.3.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.3.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.3.0-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.3.0-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.4.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.4.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.4.0-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.4.0-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.5.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.11-cert3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
}
]