VYPR
Medium severity5.7NVD Advisory· Published Sep 5, 2024· Updated Jun 17, 2026

CVE-2024-42491

CVE-2024-42491

Description

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with .1 or [.1], and res_resolver_unbound is loaded, Asterisk will crash with a SEGV. To receive a patch, users should upgrade to one of the following versions: 18.24.3, 20.9.3, 21.4.3, certified-18.9-cert12, certified-20.7-cert2. Two workarounds are available. Disable res_resolver_unbound by setting noload = res_resolver_unbound.so in modules.conf, or set rewrite_contact = yes on all PJSIP endpoints. NOTE: This may not be appropriate for all Asterisk configurations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

24
  • cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*
    Range: <18.24.3
  • cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*range: <18.9
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:-:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*
  • Asterisk/Asteriskllm-fuzzy2 versions
    18.24.3, 20.9.3, 21.4.3, 18.9-cert12, 20.7-cert2+ 1 more
    • (no CPE)range: 18.24.3, 20.9.3, 21.4.3, 18.9-cert12, 20.7-cert2
    • (no CPE)range: < 18.24.3
  • Range: 18.9-cert12, 20.7-cert2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.