CVE-2018-7286: Debian Linux
Medium severity, CVSS 6.5. EPSS: 52.7% chance of exploitation in the next 30 days.
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.
Affected products
- Debian Debian Linux: version 9.0 only
- Digium Asterisk: from 14.0.0, up to and including 14.7.5; from 15.0.0, up to and including 15.2.1; version 13.19.1 only
- Digium Certified Asterisk: up to and including 13.18
Published 2018-02-22. Last modified 2026-06-17.