Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Digium Asterisk 缓冲区错误漏洞
Vulnerability Description
Digium Asterisk是美国Digium公司的一套开源电话交换机(PBX)系统软件。该软件支持语音信箱、多方语音会议、交互式语音应答(IVR)等。 Digium Asterisk 15.6.2之前的15.x版本和16.0.1之前的16.x版本中的DNS SRV和NAPTR查询存在缓冲区溢出漏洞,该漏洞源于程序使用压缩之后的长度而不是扩展之后的长度来匹配缓冲区的大小。远程攻击者可借助特制的DNS SRV或NAPTR响应利用该漏洞造成Asterisk崩溃。
CVSS Information
N/A
Vulnerability Type
N/A