Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.
{
"binaries": [
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-dahdi-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-dbg"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-doc"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-mobile-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-modules-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-mp3-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-mysql-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-ooh323-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-voicemail"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-voicemail-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-voicemail-imapstorage"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-voicemail-imapstorage-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-voicemail-odbcstorage"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-voicemail-odbcstorage-dbgsym"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-vpb"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4",
"binary_name": "asterisk-vpb-dbgsym"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-dahdi-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-doc"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mobile-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-modules-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mp3-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mysql-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-ooh323-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-tests"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-tests-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-imapstorage"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-imapstorage-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-odbcstorage"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-odbcstorage-dbgsym"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-vpb"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-vpb-dbgsym"
}
],
"availability": "No subscription required"
}