{"id":"CVE-2019-18976","details":"An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.","modified":"2026-05-28T04:05:07.206321758Z","published":"2019-11-22T17:15:11.833Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","extracted_events":[{"last_affected":"9.0"}],"cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"http://downloads.asterisk.org/pub/security/AST-2019-008.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/04/msg00001.html"},{"type":"ADVISORY","url":"https://packetstormsecurity.com/files/155436/Asterisk-Project-Security-Advisory-AST-2019-008.html"},{"type":"ADVISORY","url":"https://seclists.org/fulldisclosure/2019/Nov/20"},{"type":"ADVISORY","url":"https://www.asterisk.org/downloads/security-advisories"},{"type":"ADVISORY","url":"https://www.cybersecurity-help.cz/vdb/SB2019112218?affChecked=1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"85335355efb2d7914a1fe20ed31afcef15fd210c"},{"last_affected":"fb53d3a79072ed172de6a0b88b801fdf9131d079"},{"introduced":"0"},{"last_affected":"f71a36701674cf50c47d91c403e824b9cc4868a7"},{"last_affected":"d661052e6d2eddae58bec5a04229c105d11e18f4"},{"last_affected":"742007f881f8cb04fe543fba4dbe5404589d9f14"},{"last_affected":"ab699aa653ffbf9efe11fef940dd2cb0a80b075e"},{"last_affected":"bb3e299589a06b7cf5bdd06a117332eaf3cf0f4d"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"extracted_events":[{"introduced":"13.0.0"},{"last_affected":"13.29.1"},{"introduced":"0"},{"last_affected":"13.21"},{"last_affected":"13.21-cert1"},{"last_affected":"13.21-cert2"},{"last_affected":"13.21-cert3"},{"last_affected":"13.21-cert4"}],"cpe":["cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.21:*:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.21:cert1:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.21:cert2:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.21:cert3:*:*:*:*:*:*","cpe:2.3:a:digium:certified_asterisk:13.21:cert4:*:*:*:*:*:*"]}}],"versions":["13.29.1","13.29.0","13.29.0-rc2","13.29.0-rc1","certified/13.21-cert4","certified/13.21-cert3","certified/13.21-cert2","13.21.0","certified/13.21-cert1","13.21.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-18976.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}