CVE-2017-7617
Last modified
CVE-2017-7617 is a vulnerability of currently unknown severity. Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.. EPSS estimates a 6.24% chance of exploitation in the next 30 days.
Description
Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Digium | Asterisk | 13.0.0 | — |
| Digium | Asterisk | 13.0.1 | — |
| Digium | Asterisk | 13.0.2 | — |
| Digium | Asterisk | 13.1.0 | — |
| Digium | Asterisk | 13.1.1 | — |
| Digium | Asterisk | 13.2.0 | — |
| Digium | Asterisk | 13.2.1 | — |
| Digium | Asterisk | 13.3.0 | Rc1 |
| Digium | Asterisk | 13.3.2 | — |
| Digium | Asterisk | 13.4.0 | — |
| Digium | Asterisk | 13.5.0 | — |
| Digium | Asterisk | 13.6.0 | Rc1 |
| Digium | Asterisk | 13.7.0 | Rc1 |
| Digium | Asterisk | 13.7.1 | — |
| Digium | Asterisk | 13.7.2 | — |
| Digium | Asterisk | 13.8.0 | — |
| Digium | Asterisk | 13.8.1 | — |
| Digium | Asterisk | 13.8.2 | — |
| Digium | Asterisk | 13.9.0 | — |
| Digium | Asterisk | 13.9.1 | — |
| Digium | Asterisk | 13.10.0 | — |
| Digium | Asterisk | 13.11.0 | — |
| Digium | Asterisk | 13.11.1 | — |
| Digium | Asterisk | 13.11.2 | — |
| Digium | Asterisk | 13.12 | — |
| Digium | Asterisk | 13.12.0 | — |
| Digium | Asterisk | 13.12.1 | — |
| Digium | Asterisk | 13.12.2 | — |
| Digium | Asterisk | 13.13 | — |
| Digium | Asterisk | 13.13.0 | — |
| Digium | Asterisk | 13.14.0 | — |
| Digium | Asterisk | 14.0 | — |
| Digium | Asterisk | 14.0.0 | — |
| Digium | Asterisk | 14.0.1 | — |
| Digium | Asterisk | 14.0.2 | — |
| Digium | Asterisk | 14.1 | — |
| Digium | Asterisk | 14.01 | — |
| Digium | Asterisk | 14.1.0 | — |
| Digium | Asterisk | 14.1.1 | — |
| Digium | Asterisk | 14.1.2 | — |
| Digium | Asterisk | 14.02 | — |
| Digium | Asterisk | 14.2 | — |
| Digium | Asterisk | 14.2.0 | — |
| Digium | Asterisk | 14.2.1 | — |
| Digium | Asterisk | 14.3.0 | — |
| Digium | Certified Asterisk | <= 13.13-cert2 | — |
References
- http://downloads.asterisk.org/pub/security/AST-2017-001.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/97377Third Party Advisory, VDB Entry
- https://bugs.debian.org/859910Patch, Third Party Advisory
- http://downloads.asterisk.org/pub/security/AST-2017-001.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/97377Third Party Advisory, VDB Entry
- https://bugs.debian.org/859910Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7617?
How severe is CVE-2017-7617?
How do I fix CVE-2017-7617?
Are you affected by CVE-2017-7617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
