CVE-2007-3764

Asterisk < 0.4 - Denial of Service

Title source: rule

Description

The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a certain data length value in a crafted packet, which results in an "overly large memcpy."

Exploits (1)

exploitdb WORKING POC VERIFIED
by fbffff · cdosmultiple
https://www.exploit-db.com/exploits/4196

Scores

EPSS 0.4563
EPSS Percentile 97.6%

Details

Status published
Products (36)
asterisk/asterisk 1.0
asterisk/asterisk 1.0.6
asterisk/asterisk 1.0.7
asterisk/asterisk 1.0.8
asterisk/asterisk 1.0.9
asterisk/asterisk 1.0.10
asterisk/asterisk 1.0.11
asterisk/asterisk 1.0.12
asterisk/asterisk 1.2.0_beta1
asterisk/asterisk 1.2.0_beta2
... and 26 more
Published Jul 18, 2007
Tracked Since Feb 18, 2026