CVE-2017-17850
7.5
HIGH
CVSS 3.1
EPSS 75.4%
描述
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used, Asterisk would crash. The severity of this vulnerability is somewhat mitigated if authentication is enabled. If authentication is enabled, a user would have to first be authorized before reaching the crash point.
如何修補 CVE-2017-17850
要修補 CVE-2017-17850,請將受影響套件升級到下列已修補版本。
- —升級至 1:13.18.5~dfsg-1 或更新版本
CVE-2017-17850 正在被利用嗎?
可能 — EPSS 為 75.4%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1:13.18.5~dfsg-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |