CVE-2017-7617
Last modified
CVE-2017-7617 is a vulnerability of currently unknown severity. Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.. EPSS estimates a 6.24% chance of exploitation in the next 30 days.
Description
Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Digium | Asterisk | 13.0.0 | — |
| Digium | Asterisk | 13.0.1 | — |
| Digium | Asterisk | 13.0.2 | — |
| Digium | Asterisk | 13.1.0 | — |
| Digium | Asterisk | 13.1.1 | — |
| Digium | Asterisk | 13.2.0 | — |
| Digium | Asterisk | 13.2.1 | — |
| Digium | Asterisk | 13.3.0 | Rc1 |
| Digium | Asterisk | 13.3.2 | — |
| Digium | Asterisk | 13.4.0 | — |
| Digium | Asterisk | 13.5.0 | — |
| Digium | Asterisk | 13.6.0 | Rc1 |
| Digium | Asterisk | 13.7.0 | Rc1 |
| Digium | Asterisk | 13.7.1 | — |
| Digium | Asterisk | 13.7.2 | — |
| Digium | Asterisk | 13.8.0 | — |
| Digium | Asterisk | 13.8.1 | — |
| Digium | Asterisk | 13.8.2 | — |
| Digium | Asterisk | 13.9.0 | — |
| Digium | Asterisk | 13.9.1 | — |
| Digium | Asterisk | 13.10.0 | — |
| Digium | Asterisk | 13.11.0 | — |
| Digium | Asterisk | 13.11.1 | — |
| Digium | Asterisk | 13.11.2 | — |
| Digium | Asterisk | 13.12 | — |
| Digium | Asterisk | 13.12.0 | — |
| Digium | Asterisk | 13.12.1 | — |
| Digium | Asterisk | 13.12.2 | — |
| Digium | Asterisk | 13.13 | — |
| Digium | Asterisk | 13.13.0 | — |
| Digium | Asterisk | 13.14.0 | — |
| Digium | Asterisk | 14.0 | — |
| Digium | Asterisk | 14.0.0 | — |
| Digium | Asterisk | 14.0.1 | — |
| Digium | Asterisk | 14.0.2 | — |
| Digium | Asterisk | 14.1 | — |
| Digium | Asterisk | 14.01 | — |
| Digium | Asterisk | 14.1.0 | — |
| Digium | Asterisk | 14.1.1 | — |
| Digium | Asterisk | 14.1.2 | — |
| Digium | Asterisk | 14.02 | — |
| Digium | Asterisk | 14.2 | — |
| Digium | Asterisk | 14.2.0 | — |
| Digium | Asterisk | 14.2.1 | — |
| Digium | Asterisk | 14.3.0 | — |
| Digium | Certified Asterisk | <= 13.13-cert2 | — |
References
- http://downloads.asterisk.org/pub/security/AST-2017-001.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/97377Third Party Advisory, VDB Entry
- https://bugs.debian.org/859910Patch, Third Party Advisory
- http://downloads.asterisk.org/pub/security/AST-2017-001.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/97377Third Party Advisory, VDB Entry
- https://bugs.debian.org/859910Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7617?
How severe is CVE-2017-7617?
How do I fix CVE-2017-7617?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7611The check_symtab_shndx function in elflint.c in elfutils 0.1…
- CVE-2017-7612The check_sysv_hash function in elflint.c in elfutils 0.168 …
- CVE-2017-7613elflint.c in elfutils 0.168 does not validate the number of …
- CVE-2017-7614elflink.c in the Binary File Descriptor (BFD) library (aka l…
- CVE-2017-7615MantisBT through 2.3.0 allows arbitrary password reset and u…8.8
- CVE-2017-7616Incorrect error handling in the set_mempolicy and mbind comp…
- CVE-2017-7618crypto/ahash.c in the Linux kernel through 4.10.9 allows att…7.5
- CVE-2017-7619In ImageMagick 7.0.4-9, an infinite loop can occur because o…
- CVE-2017-7620MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2…
- CVE-2017-7621Cross Site Scripting Vulnerability in core-eMLi in AuroMeera…
- CVE-2017-7622dde-daemon, the daemon process of DDE (Deepin Desktop Enviro…
- CVE-2017-7623The iwmiffr_convert_row32 function in imagew-miff.c in libim…
Are you affected by CVE-2017-7617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
