Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
No PoCs from references.
- https://github.com/Rodrigo-D/astDoS
- https://github.com/dj-thd/cve2018-11235-exploit