PT-2007-3812 · Digium · Asterisk

Published

2007-05-07

·

Updated

2017-07-29

·

CVE-2007-2488

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asterisk versions prior to 20070504
Description The issue is related to the IAX2 channel driver, which does not properly null terminate data. This allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information, such as memory contents, or cause a denial of service, resulting in an application crash, by sending a frame that lacks a 0 byte.
Recommendations For versions prior to 20070504, update to a version released after 20070504 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2488
DSA-1358-1

Affected Products

Asterisk