CVE-2007-3762
published 2007-07-18CVE-2007-3762: Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.51%
91.8th percentile
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
| asterisk | asterisk | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwmp-cc64-x5pj: Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1
ghsa_unreviewed·2022-05-01
CVE-2007-3762 [HIGH] GHSA-cwmp-cc64-x5pj: Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.
OSV
CVE-2007-3762: Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1
osv·2007-07-18·CVSS 9.3
CVE-2007-3762 [CRITICAL] CVE-2007-3762: Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.
Debian
CVE-2007-3762: asterisk - Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk b...
vendor_debian·2007·CVSS 9.3
CVE-2007-3762 [CRITICAL] CVE-2007-3762: asterisk - Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk b...
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.
Scope: local
bullseye: resolved (fixed in 1:1.4.8~dfsg-1)
sid: resolved (fixed in 1:1.4.8~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=185713http://ftp.digium.com/pub/asa/ASA-2007-014.pdfhttp://secunia.com/advisories/26099http://secunia.com/advisories/29051http://security.gentoo.org/glsa/glsa-200802-11.xmlhttp://www.debian.org/security/2007/dsa-1358http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.securityfocus.com/bid/24949http://www.securitytracker.com/id?1018407http://www.vupen.com/english/advisories/2007/2563https://exchange.xforce.ibmcloud.com/vulnerabilities/35466http://bugs.gentoo.org/show_bug.cgi?id=185713http://ftp.digium.com/pub/asa/ASA-2007-014.pdfhttp://secunia.com/advisories/26099http://secunia.com/advisories/29051http://security.gentoo.org/glsa/glsa-200802-11.xmlhttp://www.debian.org/security/2007/dsa-1358http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.securityfocus.com/bid/24949http://www.securitytracker.com/id?1018407http://www.vupen.com/english/advisories/2007/2563https://exchange.xforce.ibmcloud.com/vulnerabilities/35466
2007-07-18
Published