---
title: "CVE-2017-14099\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-14099?format=md
keywords: index, follow
---

# CVE-2017-14099

Publication date 2 September 2017

Last updated 26 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2017-14099?format=md#impact-score)

Toggle side navigation

## Description

In res/res\_rtp\_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before
13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before
11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure
(media takeover in the RTP stack) is possible with careful timing by an
attacker. The "strictrtp" option in rtp.conf enables a feature of the RTP
stack that learns the source address of media for a session and drops any
packets that do not originate from the expected address. This option is
enabled by default in Asterisk 11 and above. The "nat" and "rtp\_symmetric"
options (for chan\_sip and chan\_pjsip, respectively) enable symmetric RTP
support in the RTP stack. This uses the source address of incoming media as
the target address of any sent media. This option is not enabled by
default, but is commonly enabled to handle devices behind NAT. A change was
made to the strict RTP support in the RTP stack to better tolerate late
media when a reinvite occurs. When combined with the symmetric RTP support,
this introduced an avenue where media could be hijacked. Instead of only
learning a new address when expected, the new code allowed a new source
address to be learned at all times. If a flood of RTP traffic was received,
the strict RTP support would allow the new address to provide media, and
(with symmetric RTP enabled) outgoing traffic would be sent to this new
address, allowing the media to be hijacked. Provided the attacker continued
to send traffic, they would continue to receive traffic as well.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| asterisk | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Ignored end of life |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2017-14099?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| asterisk | * Introduced by   [80b8c23](https://git.kernel.org/linus/80b8c2349c427a94a428670f1183bdc693936813),   fixed by   [cb565f9](https://git.kernel.org/linus/cb565f9b59b7879abe3cceb37e8994f00df94a17) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14099)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-14099)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-14099)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-14099)

### Other references

* <https://issues.asterisk.org/jira/browse/ASTERISK-27013>
* <http://downloads.asterisk.org/pub/security/AST-2017-005.html>
* <http://www.securitytracker.com/id/1039251>
* <https://bugs.debian.org/873907>
* <https://rtpbleed.com>
* <https://gerrit.asterisk.org/#/c/6356/>
* <https://www.cve.org/CVERecord?id=CVE-2017-14099>
