The Skinny channel driver (chan_skinny) in Asterisk Open Source before 1.4.10, AsteriskNOW before beta7, Appliance Developer Kit before 0.7.0, and Appliance s800i before 1.0.3 allows remote authenticated users to cause a denial of service (application crash) via a CAPABILITIES_RES_MESSAGE packet with a capabilities count larger than the capabilities_res_message array population.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Asterisk | * | 1.4.9 (including) |
Asterisk_appliance_developer_kit | Asterisk | * | 0.6.0 (including) |
Asterisknow | Asterisk | * | beta_6 (including) |
S800i | Asterisk | * | 1.0.2 (including) |
Asterisk | Ubuntu | dapper | * |
Asterisk | Ubuntu | edgy | * |
Asterisk | Ubuntu | feisty | * |