{"id":"CVE-2017-14099","details":"In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.","modified":"2026-04-11T12:05:01.740298Z","published":"2017-09-02T16:29:00.287Z","database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:a:digium:asterisk:11.10.1:rc1:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"11.10.1-rc1"}]},{"cpe":"cpe:2.3:a:digium:asterisk:11.4.0:rc4:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"11.4.0-rc4"}]},{"cpe":"cpe:2.3:a:digium:asterisk:14.01:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"14.01"}]},{"cpe":"cpe:2.3:a:digium:asterisk:14.02:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"last_affected":"14.02"}]}]},"references":[{"type":"ADVISORY","url":"http://downloads.asterisk.org/pub/security/AST-2017-005.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3964"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039251"},{"type":"ADVISORY","url":"https://rtpbleed.com"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201710-29"},{"type":"FIX","url":"https://bugs.debian.org/873907"},{"type":"FIX","url":"https://issues.asterisk.org/jira/browse/ASTERISK-27013"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"last_affected":"85335355efb2d7914a1fe20ed31afcef15fd210c"},{"last_affected":"658f72cb71d8b5d4063e1ec70588cd55a4c52bc2"},{"last_affected":"e5a3b1d0e751e1d9799dfeddb31d3091b31a6e96"},{"last_affected":"e7305c01f21a8e935e449e19652f96a582bd76dd"},{"last_affected":"1a9331e814407d43a2e46e24825a6eedc7f2805f"},{"last_affected":"ee7aa21e683f0b46705effb0cf9a8e0af59b0160"},{"last_affected":"ff4dbeaf3894d28de5c9e2a718702442acddcb29"},{"last_affected":"c90ce6f6c254ce6ddc032c64fe3b10e7eeb0a846"},{"last_affected":"c45c3b55247f5735f16ebfa90b38a93913dfcee6"},{"last_affected":"df5493573af6efba1fb8ec7f852e85b611eb2fcc"},{"last_affected":"5cc6bd8fe6a4ee99ecb05178e30ca35e07ba8e4f"},{"last_affected":"a254eba1d54a43c012435ee14b7a3d949af9972b"},{"last_affected":"9f52e16c269a3c18d9f50f92c4553e8e6d72e838"},{"last_affected":"e3830dec049a6b5316bcd609691df7c2d71ed4b8"},{"last_affected":"f6ad2915b308e4132df613dce59d994656f7b7a8"},{"last_affected":"933356d01000d7554810d34457a86e6d629fb026"},{"last_affected":"63d46b4e7a9b022b2cc8f870c9598afc57111677"},{"last_affected":"1639644ba71c01a03ceec06da8899b9dad62818c"},{"last_affected":"59b6e5db769d77f5f2ba41869fbcab0ae6e98696"},{"last_affected":"a0fb436eda914dca26e96d304d3c9daca2be54de"},{"last_affected":"4efe7bf05179c25b96c6a0dea401d4847c7737af"},{"last_affected":"7792775db142f515b2701e41ee25ae699ad57e4f"},{"last_affected":"211d2836de28a51a91c1cb27f1ab16eba05c9b51"},{"last_affected":"7032890c9e21d69a628b40612aa3d86147c542d9"},{"last_affected":"fad0410486b3a47743331f14fcb565b79357887c"},{"last_affected":"06f5ace1fa80ce0799c6d25954de2236a1f842c8"},{"last_affected":"45e0392397605b8c8d0d975c63e21dd7b2c951de"},{"last_affected":"ac0f73694b59317f776ea2f4b8f777327def154e"},{"last_affected":"cc1106a06ac487e54c8222f30b6cc477d90986e1"},{"last_affected":"fbdaade2645d954d9bd0191dd60a218acfa93ba1"},{"last_affected":"c30613f7923ddb339dd30b9e1ce7cb18d15f75dc"},{"last_affected":"3c4b64351bc44b26fdfbb9101501ad8e485c9e11"},{"last_affected":"a6ac89c740a9a8e9ee0e008e12df3998ea6a2492"},{"last_affected":"ec0088f7fb1d4bc744657403d2607a1ae9547c27"},{"last_affected":"35d74f5d4e15903c66abe602432df9e04049edb5"},{"last_affected":"226a7e36c538de73cee76de4183b1569bd5501e5"},{"last_affected":"7d7b52c434eb23ef470ad51d08ee4029a7078b78"},{"last_affected":"ee73af1d88c9ff6db90f70f934f5ea57b8ab0625"},{"last_affected":"fdde690e0fa2e58bf45ea2bf83962bb1c261d6e0"},{"last_affected":"7d9a0a89df7e81b6bc821e92ebdda56e7f865a4b"},{"last_affected":"7fc2c4b7843f06a1f421fadbf15a3e2afef0e1fb"},{"last_affected":"7dbe77d63946ce204611a75d5f79d37f9d624ee1"},{"last_affected":"ec97c41ac817bce13d8bd9436c35ad3ef95a9f72"},{"last_affected":"3d32a671506472457298f7ab64f6efb84088bd61"},{"last_affected":"7f9db93d8afd8879b6e5583d4556d4626d7f02ba"},{"last_affected":"552cf009c0939c8b6597708135412bdc596df4bb"},{"last_affected":"e6c7e7d08f4652f4382d72100739116cf5586932"},{"last_affected":"0800ab33b5502d3a28409f813a698e298c55a2a7"},{"last_affected":"a33aa668a56760ef54ebe78bd878809910398b54"},{"last_affected":"4d985c171d92eed50b95f542c4c15b60c84d188f"},{"last_affected":"b634297c8c7a22a6e62fd7150dea185bebf2129e"},{"last_affected":"79ceeea8f80bac8c8d5870490a013036bd83e510"},{"last_affected":"22f1f880c43a69190db29b73fede7073580bbc09"},{"last_affected":"0c00ee754b436ca926b92b469ce259e8fdc8732e"},{"last_affected":"c6d6dd133c3db3b202f1f0d457780c9a6d841e0f"},{"last_affected":"de9145e0febe6e2c83628821f4906acd89c39515"},{"last_affected":"9528429f4c9d58516525224b24ff566e189c1398"},{"last_affected":"bda53c1fe8bc378c64142da595f95605335ea281"},{"last_affected":"82e513d699311c1e5b1b96639147da2b9a4441e8"},{"last_affected":"b633f5ac9497824f5bdd67657a04c94aabc88e0c"},{"last_affected":"a92aa59c1df5092ad92b7fd1641841bf31f063fb"},{"last_affected":"dabf482ce43ef37f4cef7a85e7971382b506f5c8"},{"last_affected":"106c33d20fe0709159a6c57c970cc95a98bfba9f"},{"last_affected":"2f573737b0360acc150110f11c6038bf072f1d30"},{"last_affected":"37cde9225d9526e465698b958a6720d8e33709be"},{"last_affected":"be10e65384ecaf320aec5e8a0598db618ec28084"},{"last_affected":"24e12d30603cf14aabe87376a18abdb01d3c1999"},{"last_affected":"c5a7c007aa7c1369e48d6db1c1c2f885371c1f51"},{"last_affected":"4c348e78e02c291e997abacf8ea00376b23efebb"},{"last_affected":"b5b3cf89410fecfd7f4a689e6947e7aff008f086"},{"last_affected":"2af4e887ede2b38a6c8d4c8d32f1e2177ea1bc24"},{"last_affected":"4ab2002a77ea606282631f96de73009e7b60d45a"},{"last_affected":"0356032772b3b5074a85676f4b616bbbdd68ed50"},{"last_affected":"0f8d2744dce295cd0629e26b07cd51ad4bf5da9a"},{"last_affected":"684b0dde49a68d4bcfb70ca6ce2c27f6bcddaad7"},{"last_affected":"bf9a299c759d612386f0c2293f9a490b6fd79bb1"},{"last_affected":"39df1c5a06b3e0155b9f28118b842ce45fbc8e94"},{"last_affected":"0a1b924030d38524f9d645457fbbb82cb05b00bb"},{"last_affected":"8effd766a94a3e12392975551dd3827568f439f7"},{"last_affected":"dbead3dd974c8ebf16577f579dccfb75de53b478"},{"last_affected":"affbc6907eb544bc6e049085de91002ca24ff930"},{"last_affected":"f8d503582c3506e2a65e1ec96b4f2c0833623666"},{"last_affected":"3585f89d44655687c55176e74bae4c0b5b5e77db"},{"last_affected":"c41eb44de9da1614b86fe3b5d0bf535c17e2e656"},{"last_affected":"2fd9440b5809e4a1a8b075867c902bd6a9965e13"},{"last_affected":"d880cb4af7ec79941688bf7a93e710321b618795"},{"last_affected":"8ed31147ca2cac0efe354faa75249bf08b362af7"},{"last_affected":"e14cc5edb2176fc0e8153daf27d74b958f93e639"},{"last_affected":"c8107eefe9ea1f336fc0eafc0a215381a568f087"},{"last_affected":"249bb3e7296bbef2daaf889f74807ef6cac407d6"},{"last_affected":"6e27c017c73d2eaf74631d93dfb8aaf756a517ac"},{"last_affected":"6802552203878e1c33e1812ad60a68db30d2fa24"},{"last_affected":"e70b66157732cfba5e2c94030f2666030851335c"},{"last_affected":"fea3b67d432b51a8d8cd5bd544acee6f66d9b25c"},{"last_affected":"19533f3faeb345568d2aea9bbc7fd841f962e815"},{"last_affected":"4205e661092e4e469a5e6f50f860202032bef2c3"},{"last_affected":"a0b9ab019832207882dfb1c6ace1f8c920074ce9"},{"last_affected":"adf51fff8f5264aae1ea6cbe7cb90ffdd5dd28af"},{"last_affected":"3f2411a18dd2c71225a706af2fed6e2e719da727"},{"last_affected":"d2cd4e58d8bb442bc13d3bd10879d3565fc78ab2"},{"last_affected":"eaaf1789b031583a77b377c425b4870694e7ef69"},{"last_affected":"20d6fa772155d115c7ab2cedd51f84a45549420d"},{"last_affected":"8ed9689bbffbd84451287a2687872b38d4fc7e7d"},{"last_affected":"61a50ebecf19f7ca9305a10fb1a2490d76f44550"},{"last_affected":"c0cf3631991c2e85fb23c9e83dc8e185d129aa1b"},{"last_affected":"930582391da595e850a9c1ee3b6fe9445855c9bf"},{"last_affected":"2157c83db3604fdab1892f330146d935ead75c97"},{"last_affected":"a06b72ee1e806d783e1a9af1ab61e544278be55a"},{"last_affected":"e343034f6681afff6a0d070c30dbd8c81914f9bc"},{"last_affected":"d838fa44004f18e291a56ff2dabe6f83b60cd577"},{"last_affected":"fd869fd9a4a56c7fe08b728f8b086f1341950095"},{"last_affected":"3909aa2e73f09988c1b825bd8a09404e7966771d"},{"last_affected":"bbe6d18471f4a2dee52959a462163f3ac6b20b32"},{"last_affected":"c1c8b3c5f36d46b11e49216ec03e438aee88aa2f"},{"last_affected":"b8336252bed3de5a7d0da8a2bfc98f6547cdfb6d"},{"last_affected":"8fe7e4679a9caf62d4e86419d2746d0feb56270c"},{"last_affected":"155bff138212257ca6ed34a824a5dfe3ed830830"},{"last_affected":"a663c6ac431862eb0ff37d61998446a4a8f3f595"},{"last_affected":"cb5d32bd705344af7241d1769b12d2e3b62da56e"},{"last_affected":"0ae8d2ed7cdf3e6439f8dc98a1082da1f38e0459"},{"last_affected":"614fc2b6ee64a966c67e11cf04c605afde7b2e30"},{"last_affected":"294da68ab62b662940fb623affa6ea3b03be338e"},{"last_affected":"5e0c36bb87280122c60f0be52ff420a7ef244f72"},{"last_affected":"e1736c6dd59d0ce46f51432c9c18de7ac5f78241"},{"last_affected":"930bd0a821e3271f4aa39bef9f961ac51e358871"},{"last_affected":"7d40aebf048ce13eccc3bf44f58bb61e67f27c4f"},{"last_affected":"50f15e8d121d5ba7b5eb99aab25fe6650655f3e6"},{"last_affected":"ceb4fdd341abc0e7e06a7d58767cc082dadbd32c"},{"last_affected":"93fdd80012ed2ede44844f458136970020e7f718"},{"last_affected":"d3b0e8ed7a8aa5440305147545e22ce6b5d9cdba"},{"last_affected":"208bd3475012cf6491ef93a515e80860b7b976ba"},{"last_affected":"8b8d8a305b8579c4b89aad9ddd9449fcf849f130"},{"last_affected":"6e33ac9205a56fc4232894cfdd13cf216f7662e0"},{"last_affected":"8aa14111af9ddf8909c71f86929ed1d4697466a9"},{"last_affected":"f6f483170c44642fa0267c96e6a40d8691f32d34"},{"last_affected":"caaf2326d01b555d652b821f6cf0412746055fd7"},{"last_affected":"b0614ede8b5b1e78c202652066ecc75f18eb5a87"},{"last_affected":"674742f7fffefb7445ad493a6d5aaf42f39e12ed"},{"last_affected":"e93726aec2cf7330c96843679bb6984469cfe5af"},{"last_affected":"a07795c6975b9d35ab9e1ac931748765acd2e9c3"},{"last_affected":"a2b5d4fa545dcd95535b713f5d9b906fa13c28d5"},{"last_affected":"c0e30d6457a080e43665dbe60226e6437db9f004"},{"last_affected":"2b87c28313b36f4a8f85dad8af04aad03117e139"},{"last_affected":"19e035d2e83cb68a25fe319c9e06dcb3f3b2da87"},{"last_affected":"11b0fb111b11aeaf3aaeed62601c42ca5a5b68bc"},{"last_affected":"d95f2fd9793806d400155a97e4d15bf0f33d08f9"},{"last_affected":"b40583a6e7b4bcc930cd0dd7954336bfdee879d3"},{"last_affected":"968f188ccf2eebe6834afa4411a382ad4e5b95e4"},{"last_affected":"3b1c3e8283ebc2d1f5f241e042a828ed43cc9731"},{"last_affected":"97a081e71419f1b5fbe721302db55d459be82ce3"},{"last_affected":"9eb27e03314eb37c3dd9fc9be63b85651346f70f"},{"last_affected":"49c18628e9b55cd74d7cbd46fb899a5dbb1d05d1"},{"last_affected":"8685f96aaa8a98f4ef437bdc430d7f59ce7b53d0"},{"last_affected":"2f9a1a6d749f5518dc64ef4b043abb27f263d290"},{"last_affected":"f1bfc6169ba6d6a74fcbe38b57cfd9e5607caec3"},{"last_affected":"7430e196d12454544c183259ed442fc1cab8dc70"},{"last_affected":"bf004c4584649d080979c4f877a6e9d3e793467c"},{"last_affected":"e3b1f2dfd87b098b22829ddba204a3d19c38306a"},{"last_affected":"2db4f6c01283e7491c3ee3b7507e59e5367df0ea"},{"last_affected":"dbaa5a81dbfe8a5f079ca35244cdc227c9e22873"},{"last_affected":"b20b86c0110ff91b49a6e8fe53872557153fca00"},{"last_affected":"5a25b825276c8df42d7d10579957f26d3c777fbf"},{"last_affected":"2eb8714f7c74342bb5bef4f54570f289cc43cc8b"},{"last_affected":"2a4ed773339cab64713c8f372b29e20cba298ca4"},{"last_affected":"f8fb5a74b32637bd700117d65f0b53d522e1b85d"},{"last_affected":"e2453cf2d10c7f659f6567a6fd0a01420e82b92e"},{"last_affected":"7f636d8a57264f21be9b8f546036f0acf5d3c62d"},{"last_affected":"19fb526344f10be789d52b2c444d13a2a0ba0a8b"},{"last_affected":"705735bb2bc117daa538de446da513beff02c5b8"},{"last_affected":"5b447785b61a68b24c2c1672f19659476e9b9804"},{"last_affected":"27a592b8e77ed5735c586d7230125dbe3d52e595"},{"last_affected":"33a0d64eab3db2dc863b37ce693f32e7a8fc3202"},{"last_affected":"92876c1c2a7c361108df6586387a208f67bec1cd"},{"last_affected":"47febcb9277f71089d4c072145b8e0d1b8338415"},{"last_affected":"0ef6b6960d1c46b62df9974294392192c1398adf"},{"last_affected":"c1b521ad109122b09202e0cbf4018495bed6243b"},{"last_affected":"7e17de3d6634bcfcafe3e688807665e404580475"},{"last_affected":"f3969e49d194467a3cf5316c6ab6d5d9db2eba41"}],"database_specific":{"cpe":["cpe:2.3:a:digium:asterisk:13.0.0:*:*:*:lts:*:*:*","cpe:2.3:a:digium:asterisk:13.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.0.0:beta2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.0.0:beta3:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.0.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.0.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.1.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.1.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.1.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.1.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.2.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.2.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.2.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.3.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.3.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.4.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.4.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.5.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.5.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.6.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.7.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.7.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.7.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.7.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.8.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.8.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.8.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.8.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.9.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.9.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.10.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.10.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.11.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.11.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.11.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.12:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.12.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.12.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.12.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.13:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.13.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.13.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.14.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.14.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.14.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.14.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.15.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.15.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.15.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.15.0:rc3:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.15.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.16.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.16.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.16.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.17.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:13.17.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.0:beta2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.0.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.1.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.1.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.1.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.2.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.2.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.3.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.3.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.3.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.3.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.4.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.4.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.4.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.4.0:rc3:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.4.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.5.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.5.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.5.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.6.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:14.6.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.0:beta2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.0.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.1.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.1.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.1.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.1.0:rc3:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.1.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.1.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.2.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.2.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.2.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.6.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.6.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.6.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.6.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.7.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.7.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.7.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.8.0:-:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.8.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.8.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.8.0:rc3:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.8.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.9.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.9.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.9.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.9.0:rc3:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.10.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.10.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.10.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.10.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.11.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.11.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.12.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.12.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.12.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.13.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.13.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.13.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.14.0:*:*:*:lts:*:*:*","cpe:2.3:a:digium:asterisk:11.14.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.14.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.14.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.14.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.15.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.15.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.15.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.16.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.17.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.17.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.18.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.18.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.19.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.20.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.21.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.21.0:rc2:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.21.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.21.2:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.22.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.22.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.23.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.23.0:rc1:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.23.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.24.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.24.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.25.0:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:11.25.1:*:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert1:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc1:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc2:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert10:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert11:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert12:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert13:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert14:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc1:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc2:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert15:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert16:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert2:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert3:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert4:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert5:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert6:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert7:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert8:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:11.6:cert9:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc4:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"13.0.0"},{"last_affected":"13.0.0-beta1"},{"last_affected":"13.0.0-beta2"},{"last_affected":"13.0.0-beta3"},{"last_affected":"13.0.1"},{"last_affected":"13.0.2"},{"last_affected":"13.1.0"},{"last_affected":"13.1.0-rc1"},{"last_affected":"13.1.0-rc2"},{"last_affected":"13.1.1"},{"last_affected":"13.2.0"},{"last_affected":"13.2.0-rc1"},{"last_affected":"13.2.1"},{"last_affected":"13.3.0-rc1"},{"last_affected":"13.3.2"},{"last_affected":"13.4.0"},{"last_affected":"13.4.0-rc1"},{"last_affected":"13.5.0"},{"last_affected":"13.5.0-rc1"},{"last_affected":"13.6.0-rc1"},{"last_affected":"13.7.0-rc1"},{"last_affected":"13.7.0-rc2"},{"last_affected":"13.7.1"},{"last_affected":"13.7.2"},{"last_affected":"13.8.0"},{"last_affected":"13.8.0-rc1"},{"last_affected":"13.8.1"},{"last_affected":"13.8.2"},{"last_affected":"13.9.0"},{"last_affected":"13.9.1"},{"last_affected":"13.10.0"},{"last_affected":"13.10.0-rc1"},{"last_affected":"13.11.0"},{"last_affected":"13.11.1"},{"last_affected":"13.11.2"},{"last_affected":"13.12"},{"last_affected":"13.12.0"},{"last_affected":"13.12.1"},{"last_affected":"13.12.2"},{"last_affected":"13.13"},{"last_affected":"13.13.0"},{"last_affected":"13.13.1"},{"last_affected":"13.14.0"},{"last_affected":"13.14.0-rc1"},{"last_affected":"13.14.0-rc2"},{"last_affected":"13.14.1"},{"last_affected":"13.15.0"},{"last_affected":"13.15.0-rc1"},{"last_affected":"13.15.0-rc2"},{"last_affected":"13.15.0-rc3"},{"last_affected":"13.15.1"},{"last_affected":"13.16.0"},{"last_affected":"13.16.0-rc1"},{"last_affected":"13.16.0-rc2"},{"last_affected":"13.17.0"},{"last_affected":"13.17.0-rc1"},{"last_affected":"14.0"},{"last_affected":"14.0.0"},{"last_affected":"14.0.0-beta1"},{"last_affected":"14.0.0-beta2"},{"last_affected":"14.0.0-rc1"},{"last_affected":"14.0.0-rc2"},{"last_affected":"14.0.1"},{"last_affected":"14.0.2"},{"last_affected":"14.1"},{"last_affected":"14.1.0"},{"last_affected":"14.1.1"},{"last_affected":"14.1.2"},{"last_affected":"14.2"},{"last_affected":"14.2.0"},{"last_affected":"14.2.1"},{"last_affected":"14.3.0"},{"last_affected":"14.3.0-rc1"},{"last_affected":"14.3.0-rc2"},{"last_affected":"14.3.1"},{"last_affected":"14.4.0"},{"last_affected":"14.4.0-rc1"},{"last_affected":"14.4.0-rc2"},{"last_affected":"14.4.0-rc3"},{"last_affected":"14.4.1"},{"last_affected":"14.5.0"},{"last_affected":"14.5.0-rc1"},{"last_affected":"14.5.0-rc2"},{"last_affected":"14.6.0"},{"last_affected":"14.6.0-rc1"},{"last_affected":"11.0.0"},{"last_affected":"11.0.0-beta1"},{"last_affected":"11.0.0-beta2"},{"last_affected":"11.0.0-rc1"},{"last_affected":"11.0.0-rc2"},{"last_affected":"11.0.1"},{"last_affected":"11.0.2"},{"last_affected":"11.1.0"},{"last_affected":"11.1.0-rc1"},{"last_affected":"11.1.0-rc2"},{"last_affected":"11.1.0-rc3"},{"last_affected":"11.1.1"},{"last_affected":"11.1.2"},{"last_affected":"11.2.0-rc1"},{"last_affected":"11.2.1"},{"last_affected":"11.2.2"},{"last_affected":"11.6.0"},{"last_affected":"11.6.0-rc1"},{"last_affected":"11.6.0-rc2"},{"last_affected":"11.6.1"},{"last_affected":"11.7.0"},{"last_affected":"11.7.0-rc1"},{"last_affected":"11.7.0-rc2"},{"last_affected":"11.8.0-NA"},{"last_affected":"11.8.0-rc1"},{"last_affected":"11.8.0-rc2"},{"last_affected":"11.8.0-rc3"},{"last_affected":"11.8.1"},{"last_affected":"11.9.0"},{"last_affected":"11.9.0-rc1"},{"last_affected":"11.9.0-rc2"},{"last_affected":"11.9.0-rc3"},{"last_affected":"11.10.0"},{"last_affected":"11.10.0-rc1"},{"last_affected":"11.10.1"},{"last_affected":"11.10.2"},{"last_affected":"11.11.0"},{"last_affected":"11.11.0-rc1"},{"last_affected":"11.12.0"},{"last_affected":"11.12.0-rc1"},{"last_affected":"11.12.1"},{"last_affected":"11.13.0"},{"last_affected":"11.13.0-rc1"},{"last_affected":"11.13.1"},{"last_affected":"11.14.0"},{"last_affected":"11.14.0-rc1"},{"last_affected":"11.14.0-rc2"},{"last_affected":"11.14.1"},{"last_affected":"11.14.2"},{"last_affected":"11.15.0-rc1"},{"last_affected":"11.15.0-rc2"},{"last_affected":"11.15.1"},{"last_affected":"11.16.0-rc1"},{"last_affected":"11.17.0-rc1"},{"last_affected":"11.17.1"},{"last_affected":"11.18.0"},{"last_affected":"11.18.0-rc1"},{"last_affected":"11.19.0-rc1"},{"last_affected":"11.20.0-rc1"},{"last_affected":"11.21.0-rc1"},{"last_affected":"11.21.0-rc2"},{"last_affected":"11.21.1"},{"last_affected":"11.21.2"},{"last_affected":"11.22.0"},{"last_affected":"11.22.0-rc1"},{"last_affected":"11.23.0"},{"last_affected":"11.23.0-rc1"},{"last_affected":"11.23.1"},{"last_affected":"11.24.0"},{"last_affected":"11.24.1"},{"last_affected":"11.25.0"},{"last_affected":"11.25.1"},{"last_affected":"11.6-cert1"},{"last_affected":"11.6-cert1_rc1"},{"last_affected":"11.6-cert1_rc2"},{"last_affected":"11.6-cert10"},{"last_affected":"11.6-cert11"},{"last_affected":"11.6-cert12"},{"last_affected":"11.6-cert13"},{"last_affected":"11.6-cert14"},{"last_affected":"11.6-cert14_rc1"},{"last_affected":"11.6-cert14_rc2"},{"last_affected":"11.6-cert15"},{"last_affected":"11.6-cert16"},{"last_affected":"11.6-cert2"},{"last_affected":"11.6-cert3"},{"last_affected":"11.6-cert4"},{"last_affected":"11.6-cert5"},{"last_affected":"11.6-cert6"},{"last_affected":"11.6-cert7"},{"last_affected":"11.6-cert8"},{"last_affected":"11.6-cert9"},{"last_affected":"13.13-cert1"},{"last_affected":"13.13-cert1_rc1"},{"last_affected":"13.13-cert1_rc2"},{"last_affected":"13.13-cert1_rc3"},{"last_affected":"13.13-cert1_rc4"},{"last_affected":"13.13-cert2"},{"last_affected":"13.13-cert3"},{"last_affected":"13.13-cert4"}]}}],"versions":["11.0.0","11.0.0-beta1","11.0.0-beta2","11.0.0-rc1","11.0.0-rc2","11.0.1","11.0.2","11.1.0","11.1.0-rc1","11.1.0-rc2","11.1.0-rc3","11.1.1","11.1.2","11.10.0","11.10.0-rc1","11.10.1","11.10.2","11.11.0","11.11.0-rc1","11.12.0","11.12.0-rc1","11.12.1","11.13.0","11.13.0-rc1","11.13.1","11.14.0","11.14.0-rc1","11.14.0-rc2","11.14.1","11.14.2","11.15.0","11.15.0-rc1","11.15.0-rc2","11.15.1","11.16.0-rc1","11.17.0","11.17.0-rc1","11.17.1","11.18.0","11.18.0-rc1","11.19.0-rc1","11.2.0","11.2.0-rc1","11.2.0-rc2","11.20.0-rc1","11.21.0","11.21.0-rc1","11.21.0-rc2","11.21.0-rc3","11.21.1","11.21.2","11.22.0","11.22.0-rc1","11.23.0","11.23.0-rc1","11.23.1","11.24.0","11.24.0-rc1","11.24.1","11.25.0","11.25.0-rc1","11.25.1","11.6-cert11","11.6.0","11.6.0-rc1","11.6.0-rc2","11.7.0","11.7.0-rc1","11.7.0-rc2","11.8.0","11.8.0-rc1","11.8.0-rc2","11.8.0-rc3","11.8.1","11.9.0","11.9.0-rc1","11.9.0-rc2","11.9.0-rc3","13.0.0","13.0.0-beta1","13.0.0-beta2","13.0.0-beta3","13.0.1","13.0.2","13.1.0","13.1.0-rc1","13.1.0-rc2","13.10.0","13.10.0-rc1","13.10.0-rc2","13.10.0-rc3","13.11.0","13.11.0-rc1","13.11.0-rc2","13.11.1","13.11.2","13.12.0","13.12.0-rc1","13.12.1","13.12.2","13.13.0","13.13.0-rc1","13.13.0-rc2","13.14.0","13.14.0-rc1","13.14.0-rc2","13.14.1","13.15.0","13.15.0-rc1","13.15.0-rc2","13.15.0-rc3","13.15.1","13.16.0","13.16.0-rc1","13.16.0-rc2","13.17.0","13.17.0-rc1","13.2.0","13.2.0-rc1","13.2.1","13.3.0","13.3.0-rc1","13.3.1","13.3.2","13.4.0","13.4.0-rc1","13.5.0","13.5.0-rc1","13.6.0-rc1","13.7.0","13.7.0-rc1","13.7.0-rc2","13.7.0-rc3","13.7.1","13.7.2","13.8.0","13.8.0-rc1","13.9.0","13.9.0-rc1","13.9.0-rc2","13.9.1","14.0.0","14.0.0-beta1","14.0.0-beta2","14.0.0-rc1","14.0.0-rc2","14.0.1","14.0.2","14.1.0","14.1.0-rc1","14.1.1","14.1.2","14.2.0","14.2.0-rc1","14.2.0-rc2","14.2.1","14.3.0","14.3.0-rc1","14.3.0-rc2","14.3.1","14.4.0","14.4.0-rc1","14.4.0-rc2","14.4.0-rc3","14.4.1","14.5.0","14.5.0-rc1","14.5.0-rc2","14.6.0","14.6.0-rc1","certified/11.2-cert1","certified/11.2-cert2","certified/11.6-cert1","certified/11.6-cert1-rc1","certified/11.6-cert1-rc2","certified/11.6-cert10","certified/11.6-cert11","certified/11.6-cert12","certified/11.6-cert13","certified/11.6-cert14","certified/11.6-cert14-rc1","certified/11.6-cert14-rc2","certified/11.6-cert15","certified/11.6-cert16","certified/11.6-cert2","certified/11.6-cert3","certified/11.6-cert4","certified/11.6-cert5","certified/11.6-cert6","certified/11.6-cert7","certified/11.6-cert8","certified/11.6-cert9","certified/13.1-cert1","certified/13.13-cert1","certified/13.13-cert1-rc1","certified/13.13-cert1-rc2","certified/13.13-cert1-rc3","certified/13.13-cert1-rc4","certified/13.13-cert2","certified/13.13-cert3","certified/13.13-cert4","certified/13.8-cert1","certified/13.8-cert1-rc1","certified/13.8-cert1-rc2","certified/13.8-cert1-rc3","certified/13.8-cert2","certified/13.8-cert2-rc1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14099.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}