CVE Vulnerabilities

CVE-2007-1561

Published: Mar 21, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.

Affected Software

Name Vendor Start Version End Version
Asterisk Asterisk 1.2.14 (including) 1.2.14 (including)
Asterisk Asterisk 1.2.15 (including) 1.2.15 (including)
Asterisk Asterisk 1.2.16 (including) 1.2.16 (including)
Asterisk Asterisk 1.4.1 (including) 1.4.1 (including)

References