CVE-2005-2081 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Asterisk
4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 42.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 5
Latest updateMay 1
Description
Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2005-2081: asterisk - Stack-based buffer overflow in the function that parses commands in Asterisk 1.0...↗2005