A stack-based buffer overflow in resrtpasterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession. This is caused by a signedness comparison mismatch.
{
"binaries": [
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-tests"
},
{
"binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2",
"binary_name": "asterisk-vpb"
}
]
}
{
"binaries": [
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5",
"binary_name": "asterisk-tests"
}
]
}
{
"binaries": [
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:22.5.2~dfsg+~cs6.15.60671435-1",
"binary_name": "asterisk-tests"
}
]
}
{
"binaries": [
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2",
"binary_name": "asterisk-tests"
}
]
}