CVE-2017-17664: Digium Asterisk

Medium severity, CVSS 5.9. EPSS: 32.4% chance of exploitation in the next 30 days.

A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.

Affected products

  • Digium Asterisk: from 13.0.0, before 13.18.4 (fixed in 13.18.4); from 14.0.0, before 14.7.4 (fixed in 14.7.4); from 15.0.0, before 15.1.4 (fixed in 15.1.4)
  • Digium Certified Asterisk: up to and including 13.13; version 13.13 only

Published 2017-12-13. Last modified 2026-06-17.