CVE-2019-7251: Digium Asterisk

Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.

An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation.

Affected products

  • Digium Asterisk: from 15.0.0, before 15.7.2 (fixed in 15.7.2); from 16.0.0, before 16.2.1 (fixed in 16.2.1)

Published 2019-03-28. Last modified 2026-06-17.