RULE(RULE ID:2205202)

Rule General Information
Release Date: 2021-03-26
Rule Name: Digium Asterisk pjsip_multipart_parse Denial of Service Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A denial of service vulnerability exists in Digium Asterisk. The vulnerability is due to a processing flaw in the pjsip_multipart_parse function of sip_multipart.c when the chan_pjsip module is used. A remote, unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted SIP request containing multipart data to a vulnerable Asterisk server. Successful exploitation could cause denial-of-service conditions on the target service.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.