bugs.gentoo.orgConfirmation
http://bugs.gentoo.org/show_bug.cgi?id=185713 CVE-2007-3764
Asterisk < 1.2.22/1.4.8/2.2.1 - 'chan_skinny' Remote Denial of Service
Record summary
CVE-2007-3764 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a certain data length value in a crafted packet, which results in an "overly large memcpy."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAsterisk < 1.2.22/1.4.8/2.2.1 - 'chan_skinny' Remote Denial of ServiceExploitDB exploitby fbffffNot analyzed1 file
References
12ftp.digium.comConfirmation
http://ftp.digium.com/pub/asa/ASA-2007-016.pdf 26099Third-party advisory
http://secunia.com/advisories/26099 29051Third-party advisory
http://secunia.com/advisories/29051 GLSA-200802-11Vendor advisory
http://security.gentoo.org/glsa/glsa-200802-11.xml DSA-1358Vendor advisory
http://www.debian.org/security/2007/dsa-1358 SUSE-SR:2007:015Vendor advisory
http://www.novell.com/linux/security/advisories/2007_15_sr.html 24950vdb entry
http://www.securityfocus.com/bid/24950 1018407vdb entry
http://www.securitytracker.com/id?1018407 ADV-2007-2563vdb entry
http://www.vupen.com/english/advisories/2007/2563 asterisk-skinny-driver-dos(35478)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35478 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3764