FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

asterisk -- Re-invite with T.38 and malformed SDP causes crash

Affected packages
asterisk13 < 13.29.2

Details

VuXML ID 94c6951a-0d04-11ea-87ca-001999f8d30b
Discovery 2019-11-07
Entry 2019-11-22

The Asterisk project reports:

If Asterisk receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a crash will occur.

References

CVE Name CVE-2019-18976
URL https://downloads.asterisk.org/pub/security/AST-2019-008.html