CVE-2007-1306
Asterisk 1.2-1.4 - Denial of Service via SIP Packet Without URI and SIP-Version Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1306. PoCs published by fbffff.
AI-analyzed exploit summary This exploit targets a segmentation fault vulnerability in Asterisk's SIP channel driver by sending a malformed REGISTER request. The PoC demonstrates a DoS condition by crashing the Asterisk server.
Description
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.
Exploits (1)
This exploit targets a segmentation fault vulnerability in Asterisk's SIP channel driver by sending a malformed REGISTER request. The PoC demonstrates a DoS condition by crashing the Asterisk server.