cbcvebase.
CVE-2007-3763
published 2007-07-18

CVE-2007-3763: The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance…

PriorityP430medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
26.56%
97.8th percentile
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk
asteriskasterisk

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.