CVE-2019-18976: Debian Linux
High severity, CVSS 7.5. EPSS: 12.8% chance of exploitation in the next 30 days.
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.
Affected products
- Debian Debian Linux: version 9.0 only
- Digium Asterisk: from 13.0.0, up to and including 13.29.1
- Digium Certified Asterisk: version 13.21 only
Published 2019-11-22. Last modified 2026-06-17.