{"id":"ALPINE-CVE-2023-49786","details":"Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. Commit d7d7764cb07c8a1872804321302ef93bf62cba05 contains a fix, which is part of versions 18.20.1, 20.5.1, 21.0.1, amd 18.9-cert6.","modified":"2026-09-15T08:17:47.863566750Z","published":"2023-12-14T20:15:52.927Z","upstream":["CVE-2023-49786"],"references":[{"type":"ADVISORY","url":"https://security.alpinelinux.org/vuln/CVE-2023-49786"}],"affected":[{"package":{"name":"asterisk","ecosystem":"Alpine:v3.16","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"18.20.2-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.17","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"18.20.2-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.18","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"18.20.2-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.19","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"20.5.1-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.20","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"20.5.1-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.21","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"20.5.1-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.22","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"20.5.1-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.23","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"20.5.1-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}},{"package":{"name":"asterisk","ecosystem":"Alpine:v3.24","purl":"pkg:apk/alpine/asterisk?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"20.5.1-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2023-49786.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}