Security Advisory

CVE-2021-26717

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-18 19:39:46
Last updated 2024-08-03 20:33:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, then Asterisk would crash.