CVE-2017-17090

Source
https://cve.org/CVERecord?id=CVE-2017-17090
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17090.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-17090
Downstream
Published
2017-12-02T00:29:00.247Z
Modified
2026-03-17T06:33:55.678977Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in chanskinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chanskinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.

References

Affected packages

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert1_rc1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert1_rc2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert1_rc3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert1_rc4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.13-cert7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "13.8.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "14.7.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "15.1.2"
        }
    ]
}

Affected versions

13.*
13.13.0
13.13.0-rc1
13.13.0-rc2
13.8.0
13.8.0-rc1
14.*
14.7.0
14.7.0-rc1
14.7.0-rc2
14.7.1
14.7.2
certified/13.*
certified/13.8-cert1
certified/13.8-cert1-rc1
certified/13.8-cert1-rc2
certified/13.8-cert1-rc3
certified/13.8-cert2
certified/13.8-cert2-rc1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17090.json"