---
title: "CVE-2016-9937\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-9937?format=md
keywords: index, follow
---

# CVE-2016-9937

Publication date 12 December 2016

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2016-9937?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in Asterisk Open Source 13.12.x and 13.13.x before
13.13.1 and 14.x before 14.2.1. If an SDP offer or answer is received with
the Opus codec and with the format parameters separated using a space the
code responsible for parsing will recursively call itself until it crashes.
This occurs as the code does not properly handle spaces separating the
parameters. This does NOT require the endpoint to have Opus configured in
Asterisk. This also does not require the endpoint to be authenticated. If
guest is enabled for chan\_sip or anonymous in chan\_pjsip an SDP offer or
answer is still processed and the crash occurs.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| asterisk | 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9937)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-9937)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-9937)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-9937)

### Other references

* <http://downloads.asterisk.org/pub/security/AST-2016-008.html>
* <http://downloads.asterisk.org/pub/security/AST-2016-008-13.diff>
* <http://downloads.asterisk.org/pub/security/AST-2016-008-14.diff>
* <https://issues.asterisk.org/jira/browse/ASTERISK-26579>
* <https://www.cve.org/CVERecord?id=CVE-2016-9937>
