Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2726

Опубликовано: 12 авг. 2009
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.8

Описание

The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP.

РелизСтатусПримечание
dapper

ignored

end of life, was deferred
devel

not-affected

1.6.2
hardy

ignored

end of life
intrepid

ignored

end of life, was deferred
jaunty

ignored

end of life, was deferred
karmic

not-affected

1.6.2
lucid

not-affected

1.6.2
maverick

not-affected

1.6.2
natty

not-affected

1.6.2
upstream

released

1:1.6.2.0~dfsg~beta4-0ubuntu2

Показывать по

EPSS

Процентиль: 97%
0.3069
Средний

7.8 High

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP.

debian
больше 16 лет назад

The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1. ...

github
больше 3 лет назад

The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP.

EPSS

Процентиль: 97%
0.3069
Средний

7.8 High

CVSS2