ESB-2017.3206 - [Win][UNIX/Linux] Asterisk: Denial of service - Remote/unauthenticated 2017-12-15

Printable version
PGP/GPG verifiable version

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2017.3206
                    Asterisk Project patches Remote DoS
                             15 December 2017

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Asterisk
Publisher:         Digium
Operating System:  Windows
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade

Original Bulletin: 
   http://downloads.digium.com/pub/security/AST-2017-012.html

- --------------------------BEGIN INCLUDED TEXT--------------------

               Asterisk Project Security Advisory - AST-2017-012

          Product         Asterisk                                            
          Summary         Remote Crash Vulnerability in RTCP Stack            
     Nature of Advisory   Denial of Service                                   
       Susceptibility     Remote Unauthenticated Sessions                     
          Severity        Moderate                                            
       Exploits Known     No                                                  
        Reported On       October 30, 2017                                    
        Reported By       Tzafrir Cohen and Vitezslav Novy                    
         Posted On        December 13, 2017                                   
      Last Updated On     December 12, 2017                                   
      Advisory Contact    Jcolp AT digium DOT com                             
          CVE Name        

    Description  If a compound RTCP packet is received containing more than   
                 one report (for example a Receiver Report and a Sender       
                 Report) the RTCP stack will incorrectly store report         
                 information outside of allocated memory potentially causing  
                 a crash.                                                     
                                                                              
                 For all versions of Asterisk this vulnerability requires an  
                 active call to be established.                               
                                                                              
                 For versions of Asterisk 13.17.2, 14.6.2, 15.0.0,            
                 13.13-cert6 and greater an additional level of security is   
                 placed upon RTCP packets. If the probation period for        
                 incoming RTP traffic has passed any received RTCP packets    
                 must contain the same SSRC as the RTP traffic. If the RTCP   
                 packets do not then they are dropped. This ensures other     
                 parties can not inject RTCP packets without they themselves  
                 establishing an active call.                                 

    Resolution  The RTCP stack has been changed so the report information is  
                always stored in allocated memory. The provided patches can   
                be applied to the appropriate version or the latest version   
                of Asterisk can be installed to receive the fix.              

                               Affected Versions
                Product              Release Series  
         Asterisk Open Source             13.x       All Versions             
         Asterisk Open Source             14.x       All Versions             
         Asterisk Open Source             15.x       All Versions             
          Certified Asterisk             13.13       All Versions             

                                  Corrected In
                 Product                              Release                 
           Asterisk Open Source               13.18.4, 14.7.4, 15.1.4         
            Certified Asterisk                      13.13-cert9               

                                     Patches                          
                                SVN URL                               Revision  
   http://downloads.asterisk.org/pub/security/AST-2017-012-13.diff    Asterisk  
                                                                      13        
   http://downloads.asterisk.org/pub/security/AST-2017-012-14.diff    Asterisk  
                                                                      14        
   http://downloads.asterisk.org/pub/security/AST-2017-012-15.diff    Asterisk  
                                                                      15        
   http://downloads.asterisk.org/pub/security/AST-2017-012-13.13.diff Certified 
                                                                      Asterisk  
                                                                      13.13     

       Links     https://issues.asterisk.org/jira/browse/ASTERISK-27382       
                                                                              
                 https://issues.asterisk.org/jira/browse/ASTERISK-27429       

    Asterisk Project Security Advisories are posted at                        
    http://www.asterisk.org/security                                          
                                                                              
    This document may be superseded by later versions; if so, the latest      
    version will be posted at                                                 
    http://downloads.digium.com/pub/security/AST-2017-012.pdf and             
    http://downloads.digium.com/pub/security/AST-2017-012.html                

                                Revision History
          Date                 Editor                  Revisions Made         
    November 30, 2017  Joshua Colp              Initial Revision              

               Asterisk Project Security Advisory - AST-2017-012
               Copyright © 2017 Digium, Inc. All Rights Reserved.
  Permission is hereby granted to distribute and publish this advisory in its
                           original, unaltered form.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWjNUYIx+lLeg9Ub1AQjuFQ//eXJ+QX+ZtEHYH63TnCprS8rRzaxVZAD3
yDom+6q8BTtfbFuh7f8CEi97vbKfpmrWgszv4mOHLIDKvD5JfBceA0dO9UW3hD+t
A/6lBWuQA3LWxe9mNX7jij5Uqj8BLw8j700BHnXtrqJWCrbD7tf1DTUDjZR3o8ay
wFertxNVUJ+57L2nWl0VJmsBVvS3vb2dehL0zR2xTHyTC6ChDqt6IoUpZZoov1Qx
5ihDSoGvN8XRWUVJ4INXFUtUL700KkY8g3fCbKylxDnHm4hFDp3tQDsNsJuvIfOa
A7In6JfEN3Uw25FjfUW1BrKUICv1GztGvECi6OwmLAgzmRaaX/FwRJTOQUpQxztx
ot5jAxU9CUKr/oR8oFRqyGks/msdRH3NBHtUBonE11kUJQKB3QTLbVuJB+G8xOhF
9C/PyhWtEpb+4djQeIbmB7OsYgLa2kh/J7JC2W/HanGePhg60fjTRFeVfNuu8MpV
RTd+9PDJVXi5sOcq1zQZrkYwebdK6efnVLT/3WAkReiKwbFER3PFRyfK3Ivm8eu/
BmVFP0mWJ+fAVTxNfJ9lUByR5jsmZ+lTLjlpUagLy/JFj0e6/1VZgKsZPWF8wVxu
gVSCCofSpvTKxNd5s8d9sIOvIfi2/r5MxvF14hr2IfPbbNjKegqefnv9gvvvTxUL
Gfjd0SQ7nqc=
=rpim
-----END PGP SIGNATURE-----

« Back to bulletins