CVE-2007-2488 — Asterisk vulnerability
4 documents4 sources
Severity
10.0CRITICALNVD
EPSS
3.2%
top 13.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateMay 1
Description
The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-w22m-8gr9-p75j: The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss o↗2022-05-01
OSV▶
CVE-2007-2488: The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss o↗2007-05-07
📋Vendor Advisories
1Debian▶
CVE-2007-2488: asterisk - The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properl...↗2007