HIGH · 7.1

CVE-2008-1923

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP ...

Vulnerability Description

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
AsteriskAsterisk Appliance Developer KitAll versions
AsteriskAsterisk Business Edition<= b2.5.1
AsteriskAsterisknow<= 1.0.2
AsteriskOpen Source1.0
AsteriskS800I<= 1.1.0.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-1923?

CVE-2008-1923 is a vulnerability with a CVSS score of 7.1 (HIGH). The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP ...

How severe is CVE-2008-1923?

CVE-2008-1923 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1923?

Check the references section above for vendor advisories and patch information. Affected products include: Asterisk Asterisk Appliance Developer Kit, Asterisk Asterisk Business Edition, Asterisk Asterisknow, Asterisk Open Source, Asterisk S800I.