Bug#885072: asterisk: CVE-2017-17850: Crash in PJSIP resource when missing a contact header

2017-12-27 Thread Bernhard Schmidt
Control: found -1 1:13.17.0~dfsg-1 Hi, > CVE-2017-17850[0]: > | An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and > | older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP > | messages create a dialog in Asterisk. Those SIP messages must contain a > | contact

Bug#885072: asterisk: CVE-2017-17850: Crash in PJSIP resource when missing a contact header

2017-12-23 Thread Salvatore Bonaccorso
Source: asterisk Version: 1:13.18.3~dfsg-1 Severity: grave Tags: patch security upstream Forwarded: https://issues.asterisk.org/jira/browse/ASTERISK-27480 Hi, the following vulnerability was published for asterisk. CVE-2017-17850[0]: | An issue was discovered in Asterisk 13.18.4 and older,