Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with .1 or [.1], and resresolverunbound is loaded, Asterisk will crash with a SEGV. To receive a patch, users should upgrade to one of the following versions: 18.24.3, 20.9.3, 21.4.3, certified-18.9-cert12, certified-20.7-cert2. Two workarounds are available. Disable resresolverunbound by setting noload = res_resolver_unbound.so in modules.conf, or set rewrite_contact = yes on all PJSIP endpoints. NOTE: This may not be appropriate for all Asterisk configurations.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42491.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-252",
"CWE-476"
]
}{
"cpe": [
"cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:-:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "18.24.3"
},
{
"fixed": "18.9"
},
{
"introduced": "20.0.0"
},
{
"fixed": "20.9.3"
},
{
"introduced": "21.0.0"
},
{
"last_affected": "21.4.3"
},
{
"introduced": "18.9-NA"
},
{
"last_affected": "18.9-NA"
},
{
"introduced": "18.9-cert1"
},
{
"last_affected": "18.9-cert1"
},
{
"introduced": "18.9-cert1\\-rc1"
},
{
"last_affected": "18.9-cert1\\-rc1"
},
{
"introduced": "18.9-cert10"
},
{
"last_affected": "18.9-cert10"
},
{
"introduced": "18.9-cert11"
},
{
"last_affected": "18.9-cert11"
},
{
"introduced": "18.9-cert2"
},
{
"last_affected": "18.9-cert2"
},
{
"introduced": "18.9-cert3"
},
{
"last_affected": "18.9-cert3"
},
{
"introduced": "18.9-cert4"
},
{
"last_affected": "18.9-cert4"
},
{
"introduced": "18.9-cert5"
},
{
"last_affected": "18.9-cert5"
},
{
"introduced": "18.9-cert6"
},
{
"last_affected": "18.9-cert6"
},
{
"introduced": "18.9-cert7"
},
{
"last_affected": "18.9-cert7"
},
{
"introduced": "18.9-cert8"
},
{
"last_affected": "18.9-cert8"
},
{
"introduced": "18.9-cert8\\-rc1"
},
{
"last_affected": "18.9-cert8\\-rc1"
},
{
"introduced": "18.9-cert8\\-rc2"
},
{
"last_affected": "18.9-cert8\\-rc2"
},
{
"introduced": "18.9-cert9"
},
{
"last_affected": "18.9-cert9"
},
{
"introduced": "20.7-cert1"
},
{
"last_affected": "20.7-cert1"
},
{
"introduced": "20.7-cert1\\-rc1"
},
{
"last_affected": "20.7-cert1\\-rc1"
},
{
"introduced": "20.7-cert1\\-rc2"
},
{
"last_affected": "20.7-cert1\\-rc2"
},
{
"introduced": "20.7-cert2"
},
{
"last_affected": "20.7-cert2"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}