CVE-2019-7251: Digium Asterisk
Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation.
Affected products
- Digium Asterisk: from 15.0.0, before 15.7.2 (fixed in 15.7.2); from 16.0.0, before 16.2.1 (fixed in 16.2.1)
Published 2019-03-28. Last modified 2026-06-17.