CVE-2018-7286: Debian Linux

Medium severity, CVSS 6.5. EPSS: 52.7% chance of exploitation in the next 30 days.

An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Digium Asterisk: from 14.0.0, up to and including 14.7.5; from 15.0.0, up to and including 15.2.1; version 13.19.1 only
  • Digium Certified Asterisk: up to and including 13.18

Published 2018-02-22. Last modified 2026-06-17.