PT-2007-3812 · Digium · Asterisk
Published
2007-05-07
·
Updated
2017-07-29
·
CVE-2007-2488
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Asterisk versions prior to 20070504
Description
The issue is related to the IAX2 channel driver, which does not properly null terminate data. This allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information, such as memory contents, or cause a denial of service, resulting in an application crash, by sending a frame that lacks a 0 byte.
Recommendations
For versions prior to 20070504, update to a version released after 20070504 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asterisk