FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

asterisk -- pjproject/pjsip: crash when SSL socket destroyed during handshake

Affected packages
asterisk13 < 13.38.3
asterisk16 < 16.19.1
asterisk18 < 18.5.1

Details

VuXML ID 53fbffe6-ebf7-11eb-aef1-0897988a1c07
Discovery 2021-05-05
Entry 2021-07-23

The Asterisk project reports:

Depending on the timing, it's possible for Asterisk to crash when using a TLS connection if the underlying socket parent/listener gets destroyed during the handshake.

References

CVE Name CVE-2021-32686
URL https://downloads.asterisk.org/pub/security/AST-2021-009.html