Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kevin P. Fleming

#32980of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2007-3630
7.8
2007-04-26
Digium · Asterisk · CVE-2007-2297
**Name of the Vulnerable Software and Affected Versions** Asterisk versions prior to 1.2.18 Asterisk versions 1.4.x prior to 1.4.3 **Description** The issue is related to the SIP channel driver, which does not properly parse SIP UDP packets without a valid response code. This allows remote attackers to cause a denial of service, resulting in a crash. **Recommendations** For Asterisk versions prior to 1.2.18, update to version 1.2.18 or later. For Asterisk versions 1.4.x prior to 1.4.3, update to version 1.4.3 or later.