An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1040419 | vdb entry third party advisory |
http://www.securityfocus.com/bid/103120 | vdb entry third party advisory |
https://issues.asterisk.org/jira/browse/ASTERISK-27658 | vendor advisory |
http://downloads.digium.com/pub/security/AST-2018-006.html | vendor advisory |