CVE Vulnerabilities

CVE-2007-3765

Published: Jul 18, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.

Affected Software

Name Vendor Start Version End Version
Asterisk Asterisk 1.0 (including) 1.0 (including)
Asterisk Asterisk 1.0.6 (including) 1.0.6 (including)
Asterisk Asterisk 1.0.7 (including) 1.0.7 (including)
Asterisk Asterisk 1.0.8 (including) 1.0.8 (including)
Asterisk Asterisk 1.0.9 (including) 1.0.9 (including)
Asterisk Asterisk 1.0.10 (including) 1.0.10 (including)
Asterisk Asterisk 1.0.11 (including) 1.0.11 (including)
Asterisk Asterisk 1.0.12 (including) 1.0.12 (including)
Asterisk Asterisk 1.2.0_beta1 (including) 1.2.0_beta1 (including)
Asterisk Asterisk 1.2.0_beta2 (including) 1.2.0_beta2 (including)
Asterisk Asterisk 1.2.5 (including) 1.2.5 (including)
Asterisk Asterisk 1.2.6 (including) 1.2.6 (including)
Asterisk Asterisk 1.2.7 (including) 1.2.7 (including)
Asterisk Asterisk 1.2.8 (including) 1.2.8 (including)
Asterisk Asterisk 1.2.9 (including) 1.2.9 (including)
Asterisk Asterisk 1.2.10 (including) 1.2.10 (including)
Asterisk Asterisk 1.2.11 (including) 1.2.11 (including)
Asterisk Asterisk 1.2.12 (including) 1.2.12 (including)
Asterisk Asterisk 1.2.13 (including) 1.2.13 (including)
Asterisk Asterisk 1.2.14 (including) 1.2.14 (including)
Asterisk Asterisk 1.2.15 (including) 1.2.15 (including)
Asterisk Asterisk 1.2.16 (including) 1.2.16 (including)
Asterisk Asterisk 1.2.17 (including) 1.2.17 (including)
Asterisk Asterisk 1.4.1 (including) 1.4.1 (including)
Asterisk Asterisk 1.4.2 (including) 1.4.2 (including)
Asterisk Asterisk 1.4.4_2007-04-27 (including) 1.4.4_2007-04-27 (including)
Asterisk Asterisk 1.4_beta (including) 1.4_beta (including)
Asterisk Asterisk a (including) a (including)
Asterisk Asterisk b.1.3.2 (including) b.1.3.2 (including)
Asterisk Asterisk b.1.3.3 (including) b.1.3.3 (including)
Asterisk Asterisk b.2.2.0 (including) b.2.2.0 (including)
Asterisk_appliance_developer_kit Asterisk * 0.4 (including)
Asterisknow Asterisk beta_5 (including) beta_5 (including)
Asterisknow Asterisk beta_6 (including) beta_6 (including)
Asterisk Ubuntu devel *
Asterisk Ubuntu gutsy *
Asterisk Ubuntu upstream *

References