CVE Vulnerabilities

CVE-2007-1561

Published: Mar 21, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.

Affected Software

Name Vendor Start Version End Version
Asterisk Asterisk 1.2.14 (including) 1.2.14 (including)
Asterisk Asterisk 1.2.15 (including) 1.2.15 (including)
Asterisk Asterisk 1.2.16 (including) 1.2.16 (including)
Asterisk Asterisk 1.4.1 (including) 1.4.1 (including)
Asterisk Ubuntu dapper *
Asterisk Ubuntu devel *
Asterisk Ubuntu edgy *
Asterisk Ubuntu feisty *
Asterisk Ubuntu gutsy *
Asterisk Ubuntu upstream *

References