Vulnerability Description
Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 revision 109393; and s800i 1.0.x before 1.1.0.2; allows remote attackers to access the SIP channel driver via a crafted From header.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asterisk | Asterisk | a |
| Asterisk | Asterisk Appliance Developer Kit | <= 1.4 |
| Asterisk | Asterisk Business Edition | <= a |
| Asterisk | Asterisknow | <= 1.0.1 |
| Asterisk | Open Source | <= 1.2.26 |
| Asterisk | S800I | <= 1.1.0.1 |
Related Weaknesses (CWE)
References
- http://downloads.digium.com/pub/security/AST-2008-003.htmlPatch
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.html
- http://secunia.com/advisories/29426Vendor Advisory
- http://secunia.com/advisories/29456Vendor Advisory
- http://secunia.com/advisories/29470Vendor Advisory
- http://secunia.com/advisories/29782Vendor Advisory
- http://secunia.com/advisories/29957Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200804-13.xml
- http://securitytracker.com/id?1019629
- http://www.asterisk.org/node/48466
- http://www.debian.org/security/2008/dsa-1525
- http://www.securityfocus.com/archive/1/489818/100/0/threaded
- http://www.securityfocus.com/bid/28310
- http://www.vupen.com/english/advisories/2008/0928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41308
FAQ
What is CVE-2008-1332?
CVE-2008-1332 is a vulnerability with a CVSS score of 8.8 (HIGH). Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x b...
How severe is CVE-2008-1332?
CVE-2008-1332 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1332?
Check the references section above for vendor advisories and patch information. Affected products include: Asterisk Asterisk, Asterisk Asterisk Appliance Developer Kit, Asterisk Asterisk Business Edition, Asterisk Asterisknow, Asterisk Open Source.