Candidate: CVE-2019-7251 PublicDate: 2019-03-28 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7251 https://downloads.asterisk.org/pub/security/AST-2019-001.html Description: An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923690 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_asterisk: upstream_asterisk: needs-triage precise/esm_asterisk: DNE trusty_asterisk: ignored (reached end-of-life) trusty/esm_asterisk: DNE (trusty was needs-triage) xenial_asterisk: ignored (end of standard support, was needs-triage) bionic_asterisk: needs-triage cosmic_asterisk: ignored (reached end-of-life) disco_asterisk: not-affected (1:16.2.1~dfsg-1) eoan_asterisk: not-affected (1:16.2.1~dfsg-2build2) focal_asterisk: not-affected (1:16.2.1~dfsg-2build2) groovy_asterisk: not-affected (1:16.2.1~dfsg-2build2) hirsute_asterisk: not-affected (1:16.2.1~dfsg-2build2) impish_asterisk: not-affected (1:16.2.1~dfsg-2build2) jammy_asterisk: not-affected (1:16.2.1~dfsg-2build2) devel_asterisk: not-affected (1:16.2.1~dfsg-2build2)