The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Asterisk | * | 1.4.4_2007-04-27 (including) |
Asterisk | Ubuntu | dapper | * |
Asterisk | Ubuntu | devel | * |
Asterisk | Ubuntu | edgy | * |
Asterisk | Ubuntu | feisty | * |
Asterisk | Ubuntu | gutsy | * |
Asterisk | Ubuntu | hardy | * |
Asterisk | Ubuntu | intrepid | * |
Asterisk | Ubuntu | jaunty | * |
Asterisk | Ubuntu | karmic | * |