CVE-2018-17281: Debian Linux
High severity, CVSS 7.5. EPSS: 52.4% chance of exploitation in the next 30 days.
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Digium Asterisk: from 13.0.0, up to and including 13.23.0; from 14.0.0, up to and including 14.7.7; from 15.0.0, up to and including 15.6.0
- Digium Certified Asterisk: version 11.6 only; version 13.1 only; version 13.8 only; version 13.13 only; version 13.21 only
Published 2018-09-24. Last modified 2026-06-17.