CVE-2007-1595Asterisk vulnerability

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.8%
top 25.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 22
Latest updateMay 1

Description

The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/asterisk< asterisk 1:1.4.0~dfsg-1 (bullseye)
Debianasterisk/asterisk< 1:1.4.0~dfsg-1
NVDasterisk/asterisk1.2.13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2h5w-3h6g-pgqq: The Asterisk Extension Language (AEL) in pbx/pbx_ael2022-05-01
OSV
CVE-2007-1595: The Asterisk Extension Language (AEL) in pbx/pbx_ael2007-03-22

📋Vendor Advisories

1
Debian
CVE-2007-1595: asterisk - The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not prop...2007