Denial of Service Vulnerability in Sangoma Asterisk Software
CVE-2021-46837
6.5MEDIUM
What is CVE-2021-46837?
Sangoma Asterisk versions prior to 16.16.2, 17.9.3, and 18.2.2 are susceptible to a denial of service vulnerability in the res_pjsip_t38 component. An attacker can induce a crash by sending a specially crafted m=image line with a zero port in response to a T.38 re-invite initiated by the Asterisk system. This vulnerability revisits the issues discovered in CVE-2019-15297 but arises from different conditions. The resulting crash occurs due to improper handling of active topology operations, where an append should be replaced correctly to prevent system instability.