Vulnerability Name: | CVE-2007-1561 (CCN-33068) | ||||||||||||||||
Assigned: | 2007-03-19 | ||||||||||||||||
Published: | 2007-03-19 | ||||||||||||||||
Updated: | 2018-10-16 | ||||||||||||||||
Summary: | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address. | ||||||||||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 6.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C)
6.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Mar 21 2007 - 16:30:15 CDT Two new DoS Vulnerabilities in Asterisk Fixed Source: CCN Type: Full-Disclosure Mailing List, Mon Mar 19 2007 - 13:00:14 CDT Asterisk SDP DOS vulnerability Source: CCN Type: Asterisk Web site Asterisk- Downloads Source: CONFIRM Type: UNKNOWN http://asterisk.org/node/48339 Source: CCN Type: Digium Issue Tracker ID 0009313 Asterisk segfaults upon receipt of a certain SIP packet (SIP Response code 0) Source: MITRE Type: CNA CVE-2007-1561 Source: FULLDISC Type: UNKNOWN 20070319 Asterisk SDP DOS vulnerability Source: CCN Type: SA24564 Asterisk SIP INVITE Denial of Service Vulnerability Source: SECUNIA Type: UNKNOWN 24564 Source: SECUNIA Type: UNKNOWN 24719 Source: SECUNIA Type: UNKNOWN 25582 Source: GENTOO Type: UNKNOWN GLSA-200704-01 Source: CCN Type: SECTRACK ID: 1017794 Asterisk Error in Processing INVITE Messages Lets Remote Users Deny Service Source: MLIST Type: UNKNOWN [VOIPSEC] 20070319 Asterisk SDP DOS vulnerability Source: DEBIAN Type: UNKNOWN DSA-1358 Source: DEBIAN Type: DSA-1358 asterisk -- several vulnerabilities Source: CCN Type: GLSA-200704-01 Asterisk: Two SIP Denial of Service vulnerabilities Source: SUSE Type: UNKNOWN SUSE-SA:2007:034 Source: OSVDB Type: UNKNOWN 34479 Source: CCN Type: OSVDB ID: 34479 Asterisk Malformed SIP INVITE Request DoS Source: BUGTRAQ Type: UNKNOWN 20070321 Two new DoS Vulnerabilities in Asterisk Fixed Source: BID Type: Patch 23031 Source: CCN Type: BID-23031 Asterisk SIP Invite Message Remote Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1017794 Source: CONFIRM Type: UNKNOWN http://www.sineapps.com/news.php?rssid=1707 Source: VUPEN Type: UNKNOWN ADV-2007-1039 Source: XF Type: UNKNOWN asterisk-sip-invite-dos(33068) Source: XF Type: UNKNOWN asterisk-sip-invite-dos(33068) Source: SUSE Type: SUSE-SA:2007:034 Asterisk security update | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |