CVE-2007-3765 — Asterisk vulnerability
4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.9%
top 24.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 1
Description
The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages6 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2007-3765: asterisk - The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7...↗2007