CVE-2017-14099

Source
https://cve.org/CVERecord?id=CVE-2017-14099
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14099.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-14099
Downstream
Published
2017-09-02T16:29:00.287Z
Modified
2026-04-11T12:05:01.740298Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In res/resrtpasterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The "strictrtp" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The "nat" and "rtpsymmetric" options (for chansip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.

Database specific
{
    "unresolved_ranges": [
        {
            "cpe": "cpe:2.3:a:digium:asterisk:11.10.1:rc1:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "11.10.1-rc1"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:a:digium:asterisk:11.4.0:rc4:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "11.4.0-rc4"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:a:digium:asterisk:14.01:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "14.01"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "cpe": "cpe:2.3:a:digium:asterisk:14.02:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "14.02"
                }
            ],
            "source": "CPE_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Database specific
{
    "cpe": [
        "cpe:2.3:a:digium:asterisk:13.0.0:*:*:*:lts:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.0.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.0.0:beta2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.0.0:beta3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.1.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.1.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.1.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.1.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.2.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.2.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.2.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.3.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.3.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.4.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.4.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.5.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.5.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.6.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.7.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.7.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.7.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.7.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.8.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.8.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.8.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.8.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.9.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.9.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.10.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.10.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.11.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.11.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.11.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.12:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.12.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.12.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.12.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.13:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.13.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.13.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.14.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.14.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.14.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.14.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.15.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.15.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.15.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.15.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.15.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.16.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.16.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.16.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.17.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:13.17.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.0:beta2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.1.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.1.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.1.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.2.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.2.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.3.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.3.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.3.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.3.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.4.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.4.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.4.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.4.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.4.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.5.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.5.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.5.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.6.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:14.6.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.0:beta2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.1.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.1.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.1.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.1.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.1.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.1.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.2.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.2.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.2.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.6.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.6.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.6.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.6.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.7.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.7.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.7.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.8.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.8.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.8.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.8.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.8.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.9.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.9.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.9.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.9.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.10.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.10.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.10.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.10.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.11.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.11.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.12.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.12.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.12.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.13.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.13.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.13.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.14.0:*:*:*:lts:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.14.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.14.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.14.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.14.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.15.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.15.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.15.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.16.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.17.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.17.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.18.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.18.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.19.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.20.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.21.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.21.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.21.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.21.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.22.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.22.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.23.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.23.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.23.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.24.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.24.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.25.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:asterisk:11.25.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert10:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert11:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert12:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert13:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert14:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert15:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert16:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert4:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert5:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert6:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert7:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert8:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:11.6:cert9:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc4:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:*:*:*:*",
        "cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.0.0"
        },
        {
            "last_affected": "13.0.0-beta1"
        },
        {
            "last_affected": "13.0.0-beta2"
        },
        {
            "last_affected": "13.0.0-beta3"
        },
        {
            "last_affected": "13.0.1"
        },
        {
            "last_affected": "13.0.2"
        },
        {
            "last_affected": "13.1.0"
        },
        {
            "last_affected": "13.1.0-rc1"
        },
        {
            "last_affected": "13.1.0-rc2"
        },
        {
            "last_affected": "13.1.1"
        },
        {
            "last_affected": "13.2.0"
        },
        {
            "last_affected": "13.2.0-rc1"
        },
        {
            "last_affected": "13.2.1"
        },
        {
            "last_affected": "13.3.0-rc1"
        },
        {
            "last_affected": "13.3.2"
        },
        {
            "last_affected": "13.4.0"
        },
        {
            "last_affected": "13.4.0-rc1"
        },
        {
            "last_affected": "13.5.0"
        },
        {
            "last_affected": "13.5.0-rc1"
        },
        {
            "last_affected": "13.6.0-rc1"
        },
        {
            "last_affected": "13.7.0-rc1"
        },
        {
            "last_affected": "13.7.0-rc2"
        },
        {
            "last_affected": "13.7.1"
        },
        {
            "last_affected": "13.7.2"
        },
        {
            "last_affected": "13.8.0"
        },
        {
            "last_affected": "13.8.0-rc1"
        },
        {
            "last_affected": "13.8.1"
        },
        {
            "last_affected": "13.8.2"
        },
        {
            "last_affected": "13.9.0"
        },
        {
            "last_affected": "13.9.1"
        },
        {
            "last_affected": "13.10.0"
        },
        {
            "last_affected": "13.10.0-rc1"
        },
        {
            "last_affected": "13.11.0"
        },
        {
            "last_affected": "13.11.1"
        },
        {
            "last_affected": "13.11.2"
        },
        {
            "last_affected": "13.12"
        },
        {
            "last_affected": "13.12.0"
        },
        {
            "last_affected": "13.12.1"
        },
        {
            "last_affected": "13.12.2"
        },
        {
            "last_affected": "13.13"
        },
        {
            "last_affected": "13.13.0"
        },
        {
            "last_affected": "13.13.1"
        },
        {
            "last_affected": "13.14.0"
        },
        {
            "last_affected": "13.14.0-rc1"
        },
        {
            "last_affected": "13.14.0-rc2"
        },
        {
            "last_affected": "13.14.1"
        },
        {
            "last_affected": "13.15.0"
        },
        {
            "last_affected": "13.15.0-rc1"
        },
        {
            "last_affected": "13.15.0-rc2"
        },
        {
            "last_affected": "13.15.0-rc3"
        },
        {
            "last_affected": "13.15.1"
        },
        {
            "last_affected": "13.16.0"
        },
        {
            "last_affected": "13.16.0-rc1"
        },
        {
            "last_affected": "13.16.0-rc2"
        },
        {
            "last_affected": "13.17.0"
        },
        {
            "last_affected": "13.17.0-rc1"
        },
        {
            "last_affected": "14.0"
        },
        {
            "last_affected": "14.0.0"
        },
        {
            "last_affected": "14.0.0-beta1"
        },
        {
            "last_affected": "14.0.0-beta2"
        },
        {
            "last_affected": "14.0.0-rc1"
        },
        {
            "last_affected": "14.0.0-rc2"
        },
        {
            "last_affected": "14.0.1"
        },
        {
            "last_affected": "14.0.2"
        },
        {
            "last_affected": "14.1"
        },
        {
            "last_affected": "14.1.0"
        },
        {
            "last_affected": "14.1.1"
        },
        {
            "last_affected": "14.1.2"
        },
        {
            "last_affected": "14.2"
        },
        {
            "last_affected": "14.2.0"
        },
        {
            "last_affected": "14.2.1"
        },
        {
            "last_affected": "14.3.0"
        },
        {
            "last_affected": "14.3.0-rc1"
        },
        {
            "last_affected": "14.3.0-rc2"
        },
        {
            "last_affected": "14.3.1"
        },
        {
            "last_affected": "14.4.0"
        },
        {
            "last_affected": "14.4.0-rc1"
        },
        {
            "last_affected": "14.4.0-rc2"
        },
        {
            "last_affected": "14.4.0-rc3"
        },
        {
            "last_affected": "14.4.1"
        },
        {
            "last_affected": "14.5.0"
        },
        {
            "last_affected": "14.5.0-rc1"
        },
        {
            "last_affected": "14.5.0-rc2"
        },
        {
            "last_affected": "14.6.0"
        },
        {
            "last_affected": "14.6.0-rc1"
        },
        {
            "last_affected": "11.0.0"
        },
        {
            "last_affected": "11.0.0-beta1"
        },
        {
            "last_affected": "11.0.0-beta2"
        },
        {
            "last_affected": "11.0.0-rc1"
        },
        {
            "last_affected": "11.0.0-rc2"
        },
        {
            "last_affected": "11.0.1"
        },
        {
            "last_affected": "11.0.2"
        },
        {
            "last_affected": "11.1.0"
        },
        {
            "last_affected": "11.1.0-rc1"
        },
        {
            "last_affected": "11.1.0-rc2"
        },
        {
            "last_affected": "11.1.0-rc3"
        },
        {
            "last_affected": "11.1.1"
        },
        {
            "last_affected": "11.1.2"
        },
        {
            "last_affected": "11.2.0-rc1"
        },
        {
            "last_affected": "11.2.1"
        },
        {
            "last_affected": "11.2.2"
        },
        {
            "last_affected": "11.6.0"
        },
        {
            "last_affected": "11.6.0-rc1"
        },
        {
            "last_affected": "11.6.0-rc2"
        },
        {
            "last_affected": "11.6.1"
        },
        {
            "last_affected": "11.7.0"
        },
        {
            "last_affected": "11.7.0-rc1"
        },
        {
            "last_affected": "11.7.0-rc2"
        },
        {
            "last_affected": "11.8.0-NA"
        },
        {
            "last_affected": "11.8.0-rc1"
        },
        {
            "last_affected": "11.8.0-rc2"
        },
        {
            "last_affected": "11.8.0-rc3"
        },
        {
            "last_affected": "11.8.1"
        },
        {
            "last_affected": "11.9.0"
        },
        {
            "last_affected": "11.9.0-rc1"
        },
        {
            "last_affected": "11.9.0-rc2"
        },
        {
            "last_affected": "11.9.0-rc3"
        },
        {
            "last_affected": "11.10.0"
        },
        {
            "last_affected": "11.10.0-rc1"
        },
        {
            "last_affected": "11.10.1"
        },
        {
            "last_affected": "11.10.2"
        },
        {
            "last_affected": "11.11.0"
        },
        {
            "last_affected": "11.11.0-rc1"
        },
        {
            "last_affected": "11.12.0"
        },
        {
            "last_affected": "11.12.0-rc1"
        },
        {
            "last_affected": "11.12.1"
        },
        {
            "last_affected": "11.13.0"
        },
        {
            "last_affected": "11.13.0-rc1"
        },
        {
            "last_affected": "11.13.1"
        },
        {
            "last_affected": "11.14.0"
        },
        {
            "last_affected": "11.14.0-rc1"
        },
        {
            "last_affected": "11.14.0-rc2"
        },
        {
            "last_affected": "11.14.1"
        },
        {
            "last_affected": "11.14.2"
        },
        {
            "last_affected": "11.15.0-rc1"
        },
        {
            "last_affected": "11.15.0-rc2"
        },
        {
            "last_affected": "11.15.1"
        },
        {
            "last_affected": "11.16.0-rc1"
        },
        {
            "last_affected": "11.17.0-rc1"
        },
        {
            "last_affected": "11.17.1"
        },
        {
            "last_affected": "11.18.0"
        },
        {
            "last_affected": "11.18.0-rc1"
        },
        {
            "last_affected": "11.19.0-rc1"
        },
        {
            "last_affected": "11.20.0-rc1"
        },
        {
            "last_affected": "11.21.0-rc1"
        },
        {
            "last_affected": "11.21.0-rc2"
        },
        {
            "last_affected": "11.21.1"
        },
        {
            "last_affected": "11.21.2"
        },
        {
            "last_affected": "11.22.0"
        },
        {
            "last_affected": "11.22.0-rc1"
        },
        {
            "last_affected": "11.23.0"
        },
        {
            "last_affected": "11.23.0-rc1"
        },
        {
            "last_affected": "11.23.1"
        },
        {
            "last_affected": "11.24.0"
        },
        {
            "last_affected": "11.24.1"
        },
        {
            "last_affected": "11.25.0"
        },
        {
            "last_affected": "11.25.1"
        },
        {
            "last_affected": "11.6-cert1"
        },
        {
            "last_affected": "11.6-cert1_rc1"
        },
        {
            "last_affected": "11.6-cert1_rc2"
        },
        {
            "last_affected": "11.6-cert10"
        },
        {
            "last_affected": "11.6-cert11"
        },
        {
            "last_affected": "11.6-cert12"
        },
        {
            "last_affected": "11.6-cert13"
        },
        {
            "last_affected": "11.6-cert14"
        },
        {
            "last_affected": "11.6-cert14_rc1"
        },
        {
            "last_affected": "11.6-cert14_rc2"
        },
        {
            "last_affected": "11.6-cert15"
        },
        {
            "last_affected": "11.6-cert16"
        },
        {
            "last_affected": "11.6-cert2"
        },
        {
            "last_affected": "11.6-cert3"
        },
        {
            "last_affected": "11.6-cert4"
        },
        {
            "last_affected": "11.6-cert5"
        },
        {
            "last_affected": "11.6-cert6"
        },
        {
            "last_affected": "11.6-cert7"
        },
        {
            "last_affected": "11.6-cert8"
        },
        {
            "last_affected": "11.6-cert9"
        },
        {
            "last_affected": "13.13-cert1"
        },
        {
            "last_affected": "13.13-cert1_rc1"
        },
        {
            "last_affected": "13.13-cert1_rc2"
        },
        {
            "last_affected": "13.13-cert1_rc3"
        },
        {
            "last_affected": "13.13-cert1_rc4"
        },
        {
            "last_affected": "13.13-cert2"
        },
        {
            "last_affected": "13.13-cert3"
        },
        {
            "last_affected": "13.13-cert4"
        }
    ],
    "source": "CPE_FIELD"
}

Affected versions

11.*
11.0.0
11.0.0-beta1
11.0.0-beta2
11.0.0-rc1
11.0.0-rc2
11.0.1
11.0.2
11.1.0
11.1.0-rc1
11.1.0-rc2
11.1.0-rc3
11.1.1
11.1.2
11.10.0
11.10.0-rc1
11.10.1
11.10.2
11.11.0
11.11.0-rc1
11.12.0
11.12.0-rc1
11.12.1
11.13.0
11.13.0-rc1
11.13.1
11.14.0
11.14.0-rc1
11.14.0-rc2
11.14.1
11.14.2
11.15.0
11.15.0-rc1
11.15.0-rc2
11.15.1
11.16.0-rc1
11.17.0
11.17.0-rc1
11.17.1
11.18.0
11.18.0-rc1
11.19.0-rc1
11.2.0
11.2.0-rc1
11.2.0-rc2
11.20.0-rc1
11.21.0
11.21.0-rc1
11.21.0-rc2
11.21.0-rc3
11.21.1
11.21.2
11.22.0
11.22.0-rc1
11.23.0
11.23.0-rc1
11.23.1
11.24.0
11.24.0-rc1
11.24.1
11.25.0
11.25.0-rc1
11.25.1
11.6-cert11
11.6.0
11.6.0-rc1
11.6.0-rc2
11.7.0
11.7.0-rc1
11.7.0-rc2
11.8.0
11.8.0-rc1
11.8.0-rc2
11.8.0-rc3
11.8.1
11.9.0
11.9.0-rc1
11.9.0-rc2
11.9.0-rc3
13.*
13.0.0
13.0.0-beta1
13.0.0-beta2
13.0.0-beta3
13.0.1
13.0.2
13.1.0
13.1.0-rc1
13.1.0-rc2
13.10.0
13.10.0-rc1
13.10.0-rc2
13.10.0-rc3
13.11.0
13.11.0-rc1
13.11.0-rc2
13.11.1
13.11.2
13.12.0
13.12.0-rc1
13.12.1
13.12.2
13.13.0
13.13.0-rc1
13.13.0-rc2
13.14.0
13.14.0-rc1
13.14.0-rc2
13.14.1
13.15.0
13.15.0-rc1
13.15.0-rc2
13.15.0-rc3
13.15.1
13.16.0
13.16.0-rc1
13.16.0-rc2
13.17.0
13.17.0-rc1
13.2.0
13.2.0-rc1
13.2.1
13.3.0
13.3.0-rc1
13.3.1
13.3.2
13.4.0
13.4.0-rc1
13.5.0
13.5.0-rc1
13.6.0-rc1
13.7.0
13.7.0-rc1
13.7.0-rc2
13.7.0-rc3
13.7.1
13.7.2
13.8.0
13.8.0-rc1
13.9.0
13.9.0-rc1
13.9.0-rc2
13.9.1
14.*
14.0.0
14.0.0-beta1
14.0.0-beta2
14.0.0-rc1
14.0.0-rc2
14.0.1
14.0.2
14.1.0
14.1.0-rc1
14.1.1
14.1.2
14.2.0
14.2.0-rc1
14.2.0-rc2
14.2.1
14.3.0
14.3.0-rc1
14.3.0-rc2
14.3.1
14.4.0
14.4.0-rc1
14.4.0-rc2
14.4.0-rc3
14.4.1
14.5.0
14.5.0-rc1
14.5.0-rc2
14.6.0
14.6.0-rc1
certified/11.*
certified/11.2-cert1
certified/11.2-cert2
certified/11.6-cert1
certified/11.6-cert1-rc1
certified/11.6-cert1-rc2
certified/11.6-cert10
certified/11.6-cert11
certified/11.6-cert12
certified/11.6-cert13
certified/11.6-cert14
certified/11.6-cert14-rc1
certified/11.6-cert14-rc2
certified/11.6-cert15
certified/11.6-cert16
certified/11.6-cert2
certified/11.6-cert3
certified/11.6-cert4
certified/11.6-cert5
certified/11.6-cert6
certified/11.6-cert7
certified/11.6-cert8
certified/11.6-cert9
certified/13.*
certified/13.1-cert1
certified/13.13-cert1
certified/13.13-cert1-rc1
certified/13.13-cert1-rc2
certified/13.13-cert1-rc3
certified/13.13-cert1-rc4
certified/13.13-cert2
certified/13.13-cert3
certified/13.13-cert4
certified/13.8-cert1
certified/13.8-cert1-rc1
certified/13.8-cert1-rc2
certified/13.8-cert1-rc3
certified/13.8-cert2
certified/13.8-cert2-rc1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14099.json"