CVE-2017-17090: Digium Asterisk

High severity, CVSS 7.5. EPSS: 82.2% chance of exploitation in the next 30 days.

An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.

Affected products

  • Digium Asterisk: up to and including 13.8.2; up to and including 14.7.2; up to and including 15.1.2
  • Digium Certified Asterisk: up to and including 13.13; version 13.13 only

Published 2017-12-02. Last modified 2026-06-17.