Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'
CVE-2023-37457
What is CVE-2023-37457?
Inversions of Asterisk prior to version 18.20.0, 20.5.0, and 21.0.0 contain a buffer overflow risk within the PJSIP_HEADER dialplan function. This vulnerability allows an attacker to overwrite memory or potentially crash the system if the dialplan is improperly configured to update a header with data from untrusted sources. If the 'update' functionality is not utilized, the risk is mitigated. A corrective patch is available for immediate application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
asterisk <= 18.20.0 <= 18.20.0
asterisk >= 19.0.0, <= 20.5.0 <= 19.0.0, 20.5.0
asterisk = 21.0.0 = 21.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
