Learn about CVE-2019-18976, a critical vulnerability in Sangoma Asterisk versions up to 13.x and Certified Asterisk versions up to 13.21-x, leading to system crashes and potential service disruption. Find mitigation steps and preventive measures here.
A problem was found in res_pjsip_t38.c within Sangoma Asterisk versions up to 13.x and Certified Asterisk versions up to 13.21-x. This vulnerability can lead to a crash due to a NULL pointer dereference when receiving a re-invite initiating T.38 faxing with specific SDP parameters.
Understanding CVE-2019-18976
This CVE identifies a critical issue in Sangoma Asterisk and Certified Asterisk versions that can result in a system crash under certain conditions.
What is CVE-2019-18976?
CVE-2019-18976 is a vulnerability in the handling of T.38 faxing re-invites in Sangoma Asterisk and Certified Asterisk versions up to 13.21-x.
The Impact of CVE-2019-18976
The vulnerability can be exploited to cause a crash in the affected Asterisk versions, potentially leading to service disruption and denial of service.
Technical Details of CVE-2019-18976
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The issue occurs in res_pjsip_t38.c when a re-invite for T.38 faxing lacks a "c line" in the SDP and has a port of 0, triggering a NULL pointer dereference and system crash.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability is exploited by sending a specific re-invite request that triggers the T.38 faxing process without essential SDP parameters, leading to the crash.
Mitigation and Prevention
Protect your systems from CVE-2019-18976 with the following measures:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates