Security Advisory
CVE-2018-7287
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).