PT-2007-3812 · Digium · Asterisk

Publicado

2007-05-07

·

Atualizado

2017-07-29

·

CVE-2007-2488

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asterisk versions prior to 20070504
Description The issue is related to the IAX2 channel driver, which does not properly null terminate data. This allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information, such as memory contents, or cause a denial of service, resulting in an application crash, by sending a frame that lacks a 0 byte.
Recommendations For versions prior to 20070504, update to a version released after 20070504 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2488
DSA-1358-1

Produtos afetados

Asterisk