Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with `.1` or `[.1]`, and res_resolver_unbound is loaded, Asterisk will crash with a SEGV. To receive a patch, users should upgrade to one of the following versions: 18.24.3, 20.9.3, 21.4.3, certified-18.9-cert12, certified-20.7-cert2. Two workarounds are available. Disable res_resolver_unbound by setting `noload = res_resolver_unbound.so` in modules.conf, or set `rewrite_contact = yes` on all PJSIP endpoints. NOTE: This may not be appropriate for all Asterisk configurations.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
23
Affected Products
7
References
sangoma / asterisk
| - |
| sangoma | asterisk | 21.0.0 - 21.4.3 | - |
| sangoma | certified_asterisk | 18.9 | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
| sangoma | certified_asterisk | - | - |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Exploitability
Impact