漏洞描述
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
seclists.orghttp://seclists.org/fulldisclosure/2018/Sep/31↗www.securityfocus.comhttp://www.securityfocus.com/bid/105389↗security.gentoo.orghttps://security.gentoo.org/glsa/201811-11↗lists.debian.orghttps://lists.debian.org/debian-lts-announce/2018/09/msg00034.html↗downloads.asterisk.orghttp://downloads.asterisk.org/pub/security/AST-2018-009.html↗issues.asterisk.orghttps://issues.asterisk.org/jira/browse/ASTERISK-28013↗seclists.orghttps://seclists.org/bugtraq/2018/Sep/53↗www.debian.orghttps://www.debian.org/security/2018/dsa-4320↗www.securitytracker.comhttp://www.securitytracker.com/id/1041694↗packetstormsecurity.comhttp://packetstormsecurity.com/files/149453/Asterisk-Project-Security-Advisory-AST-2018-009.html↗