Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-2488

Опубликовано: 07 мая 2007
Источник: debian
EPSS Низкий

Описание

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
asteriskfixed1:1.4.5~dfsg-1package

Примечания

  • no-dsa / unimportant candidate, the opposite side of the telephone line

  • could just as well hang-up

  • https://downloads.avaya.com/elmodocs2/security/ASA-2007-013.htm

EPSS

Процентиль: 86%
0.0307
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.

nvd
больше 18 лет назад

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.

github
больше 3 лет назад

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.

EPSS

Процентиль: 86%
0.0307
Низкий