CVE-2008-1289
published 2008-03-24CVE-2008-1289: Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
11.52%
95.5th percentile
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asterisk | asterisk_appliance_developer_kit | — | — |
| asterisk | asterisk_appliance_developer_kit | >= 0 < 1:1.4.18.1~dfsg-1 | 1:1.4.18.1~dfsg-1 |
| asterisk | asterisk_business_edition | <= c.1.0-beta8 | — |
| asterisk | asterisk_business_edition | <= c.1.0beta7 | — |
| asterisk | asterisknow | <= 1.0.1 | — |
| asterisk | open_source | <= 1.4.18 | — |
| asterisk | open_source | <= 1.4.19 | — |
| asterisk | open_source | <= 1.6.0_beta5 | — |
| asterisk | s800i | <= 1.1.0.1 | — |
| debian | asterisk | < asterisk 1:1.4.18.1~dfsg-1 (bullseye) | asterisk 1:1.4.18.1~dfsg-1 (bullseye) |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: incomplete upstream fix for CVE-2008-2079
vendor_redhat·2008-07-03·CVSS 4.6
CVE-2008-4098 [MEDIUM] mysql: incomplete upstream fix for CVE-2008-2079
mysql: incomplete upstream fix for CVE-2008-2079
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
Statement: In Red Hat Enterprise Linux 5, issue CVE-2008-2079 was fixed without introducing CVE-2008-4098 in RHSA-2009:1289.
Debian
CVE-2008-1289: asterisk - Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4....
vendor_debian·2008·CVSS 7.5
CVE-2008-1289 [HIGH] CVE-2008-1289: asterisk - Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4....
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.
Scope: local
bullseye: resolved (fixed in 1:1.4.18.1~dfsg-1)
sid: resolved (fixed in 1:1.4.18.1~dfsg-1)
Red Hat
asterisk: Two buffer overflows in RTP Codec Payload Handling (AST-2008-002)
vendor_redhat·CVSS 7.5
CVE-2008-1289 [HIGH] asterisk: Two buffer overflows in RTP Codec Payload Handling (AST-2008-002)
asterisk: Two buffer overflows in RTP Codec Payload Handling (AST-2008-002)
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.
GHSA
GHSA-xjqv-ch5c-vc5h: Multiple buffer overflows in Asterisk Open Source 1
ghsa_unreviewed·2022-05-01
CVE-2008-1289 [HIGH] CWE-119 GHSA-xjqv-ch5c-vc5h: Multiple buffer overflows in Asterisk Open Source 1
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.
OSV
CVE-2008-1289: Multiple buffer overflows in Asterisk Open Source 1
osv·2008-03-24·CVSS 7.5
CVE-2008-1289 [HIGH] CVE-2008-1289: Multiple buffer overflows in Asterisk Open Source 1
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.
No detection rules found.
http://downloads.digium.com/pub/security/AST-2008-002.htmlhttp://labs.musecurity.com/advisories/MU-200803-01.txthttp://secunia.com/advisories/29426http://secunia.com/advisories/29470http://securityreason.com/securityalert/3763http://securitytracker.com/id?1019628http://www.asterisk.org/node/48466http://www.securityfocus.com/archive/1/489817/100/0/threadedhttp://www.securityfocus.com/bid/28308http://www.vupen.com/english/advisories/2008/0928https://exchange.xforce.ibmcloud.com/vulnerabilities/41302https://exchange.xforce.ibmcloud.com/vulnerabilities/41305https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00438.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00514.htmlhttp://downloads.digium.com/pub/security/AST-2008-002.htmlhttp://labs.musecurity.com/advisories/MU-200803-01.txthttp://secunia.com/advisories/29426http://secunia.com/advisories/29470http://securityreason.com/securityalert/3763http://securitytracker.com/id?1019628http://www.asterisk.org/node/48466http://www.securityfocus.com/archive/1/489817/100/0/threadedhttp://www.securityfocus.com/bid/28308http://www.vupen.com/english/advisories/2008/0928https://exchange.xforce.ibmcloud.com/vulnerabilities/41302https://exchange.xforce.ibmcloud.com/vulnerabilities/41305https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00438.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00514.html
2008-03-24
Published