HIGH · 10.0

CVE-2007-2488

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive ...

Vulnerability Description

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AsteriskAsterisk<= 1.4.4_2007-04-27

References

FAQ

What is CVE-2007-2488?

CVE-2007-2488 is a vulnerability with a CVSS score of 10.0 (HIGH). The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive ...

How severe is CVE-2007-2488?

CVE-2007-2488 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2488?

Check the references section above for vendor advisories and patch information. Affected products include: Asterisk Asterisk.