CVE-2020-28242

Source
https://cve.org/CVERecord?id=CVE-2020-28242
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28242.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-28242
Downstream
Published
2020-11-06T06:15:11.930Z
Modified
2026-07-08T05:58:45.266665292Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume more and more memory since the transaction will never terminate (even if the call is hung up), ultimately leading to a restart or shutdown of Asterisk. Outbound authentication must be configured on the endpoint for this to occur.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.0"
                },
                {
                    "last_affected": "9.0"
                }
            ],
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "debian:debian_linux"
        },
        {
            "extracted_events": [
                {
                    "introduced": "33"
                },
                {
                    "last_affected": "33"
                }
            ],
            "cpes": [
                "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "fedoraproject:fedora"
        }
    ]
}
References

Affected packages

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "16.8.0"
        },
        {
            "introduced": "13.0"
        },
        {
            "fixed": "13.37.1"
        },
        {
            "introduced": "16.0"
        },
        {
            "fixed": "16.14.1"
        },
        {
            "introduced": "17.0"
        },
        {
            "fixed": "17.8.1"
        },
        {
            "introduced": "18.0"
        },
        {
            "fixed": "18.0.1"
        }
    ],
    "cpe": [
        "cpe:2.3:a:asterisk:certified_asterisk:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*"
    ],
    "source": "CPE_RANGE"
}

Affected versions

13.*
13.37.0
13.37.0-rc1
16.*
16.14.0
16.14.0-rc1
16.8.0
16.8.0-rc1
16.8.0-rc2
17.*
17.8.0
17.8.0-rc1
18.*
18.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28242.json"