In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSangoma Asterisk
APPSangoma20.0.016.0.0 – 16.29.1 (excl.)18.0.0 – 18.15.1 (excl.)19.0.0 – 19.7.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
References
Related vulnerabilities
CVE-2024-57520CRITICAL9.8PL ✓same product
Insecure Permissions w Sangoma Asterisk v22 — tworzenie plików poza katalogiem aplikacji
CVE-2022-21723CRITICAL9.1PL ✓same product
PJSIP: odczyt poza granicami bufora przy parsowaniu multipart SIP
CVE-2025-1131HIGH7.0same product
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolk...
CVE-2025-57767HIGH7.5same product
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, ...
CVE-2025-47779HIGH7.7same product
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4...