PT-2007-3812 · Digium · Asterisk
Publicado
2007-05-07
·
Atualizado
2017-07-29
·
CVE-2007-2488
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Asterisk versions prior to 20070504
Description
The issue is related to the IAX2 channel driver, which does not properly null terminate data. This allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information, such as memory contents, or cause a denial of service, resulting in an application crash, by sending a frame that lacks a 0 byte.
Recommendations
For versions prior to 20070504, update to a version released after 20070504 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Asterisk