CVE-2019-12827: Digium Asterisk

Medium severity, CVSS 6.5. EPSS: 4.1% chance of exploitation in the next 30 days.

Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.

Affected products

  • Digium Asterisk: from 13.0.0, before 13.27.0 (fixed in 13.27.0); from 15.0.0, before 15.7.2 (fixed in 15.7.2); from 16.0.0, before 16.4.0 (fixed in 16.4.0)
  • Digium Certified Asterisk: version 13.21 only

Published 2019-07-12. Last modified 2026-06-17.