"value":"There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"n/a"
}
]
}
]
},
"references":{
"reference_data":[
{
"name":"20180920 AST-2018-009: Remote crash vulnerability in HTTP websocket upgrade",
"refsource":"BUGTRAQ",
"url":"https://seclists.org/bugtraq/2018/Sep/53"
},
{
"name":"20180920 AST-2018-009: Remote crash vulnerability in HTTP websocket upgrade",