
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message is received with a History-Info header that contains a tel-uri, or when a SIP 181 response is received that contains a tel-uri in the Diversion header (Vendor Advisory, Vendor Advisory).
The vulnerability exists in the res_pjsip_diversion.c module of Asterisk. The issue occurs when processing SIP messages containing either a History-Info header or a Diversion header with a tel-uri. The CVSS v3.1 Base Score is 6.5 MEDIUM (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The vulnerability requires the remote client to be authenticated, or Asterisk must be configured for anonymous calling for the problem to manifest (NVD).
When successfully exploited, this vulnerability results in a denial of service condition through a crash of the Asterisk service. The impact is limited to availability, with no direct impact on confidentiality or integrity of the system (Vendor Advisory).
The issue has been fixed in Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1. The fix ensures that if Asterisk receives a SIP message with a History-Info header containing a tel-uri, the redirecting cause is simply set to unknown instead of causing a crash. For the Diversion header case, similar protections were implemented to prevent crashes when processing tel-uri content (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."