CVE-2019-15639: Digium Asterisk

High severity, CVSS 7.5. EPSS: 21.9% chance of exploitation in the next 30 days.

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

Affected products

  • Digium Asterisk: from 13.0.0, up to and including 13.28.0; from 16.0.0, up to and including 16.5.0

Published 2019-09-09. Last modified 2026-06-17.