Vulnerability Name: | CVE-2007-2488 (CCN-34085) | ||||||||||||||||
Assigned: | 2007-05-04 | ||||||||||||||||
Published: | 2007-05-04 | ||||||||||||||||
Updated: | 2017-07-29 | ||||||||||||||||
Summary: | The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: CCN Type: Asterisk Web site Asterisk- Downloads Source: MITRE Type: CNA CVE-2007-2488 Source: CCN Type: ASA-2007-013 IAX2 users can cause unauthorized data disclosure Source: CONFIRM Type: UNKNOWN http://ftp.digium.com/pub/asa/ASA-2007-013.pdf Source: OSVDB Type: UNKNOWN 35769 Source: CCN Type: SA25134 Asterisk IAX2 Channel Driver Information Disclosure Source: SECUNIA Type: UNKNOWN 25134 Source: SECUNIA Type: UNKNOWN 25582 Source: DEBIAN Type: UNKNOWN DSA-1358 Source: DEBIAN Type: DSA-1358 asterisk -- several vulnerabilities Source: SUSE Type: UNKNOWN SUSE-SA:2007:034 Source: CCN Type: OSVDB ID: 35769 Asterisk IAX2 Channel Driver (chan_iax2) Remote Memory Disclosure Source: BID Type: UNKNOWN 23824 Source: CCN Type: BID-23824 Asterisk IAX2 Text Frame Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-1661 Source: XF Type: UNKNOWN asterisk-iax2-information-disclosure(34085) Source: XF Type: UNKNOWN asterisk-iax2-information-disclosure(34085) Source: SUSE Type: SUSE-SA:2007:034 Asterisk security update | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |