asterisk.orgConfirmation
http://asterisk.org/node/48319 CVE-2007-1306
Asterisk 1.2.15/1.4.0 - Remote Denial of Service
Record summary
CVE-2007-1306 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit.
Description
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAsterisk 1.2.15/1.4.0 - Remote Denial of ServiceExploitDB exploitby fbffffNot analyzed1 file
References
Showing 12 of 16asterisk.orgConfirmation
http://asterisk.org/node/48320 labs.musecurity.com
http://labs.musecurity.com/advisories/MU-200703-01.txt 24380Third-party advisory
http://secunia.com/advisories/24380 24578Third-party advisory
http://secunia.com/advisories/24578 25582Third-party advisory
http://secunia.com/advisories/25582 GLSA-200703-14Vendor advisory
http://security.gentoo.org/glsa/glsa-200703-14.xml DSA-1358Vendor advisory
http://www.debian.org/security/2007/dsa-1358 VU#228032Third-party advisory
http://www.kb.cert.org/vuls/id/228032 SUSE-SA:2007:034Vendor advisory
http://www.novell.com/linux/security/advisories/2007_34_asterisk.html 33888vdb entry
http://www.osvdb.org/33888 22838vdb entry
http://www.securityfocus.com/bid/22838