Oval Definition:oval:com.ubuntu.disco:def:201776170000000
Revision Date:2017-04-10Version:1
Title:CVE-2017-7617 on Ubuntu 19.04 (disco) - medium.
Description:Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action. Alex Villacis Lasso discovered that asterisk did not properly check the length of certain input. A remote attacker could use this vulnerability to cause a denial of service (crash) or potentially execute arbitrary code.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-7617
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND asterisk package in disco, is related to the CVE in some way and has been fixed (note: '1:13.18.3~dfsg-1ubuntu4').
  • BACK