CVE-2019-18976: Debian Linux

High severity, CVSS 7.5. EPSS: 12.8% chance of exploitation in the next 30 days.

An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Digium Asterisk: from 13.0.0, up to and including 13.29.1
  • Digium Certified Asterisk: version 13.21 only

Published 2019-11-22. Last modified 2026-06-17.