main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Digium | 1.6.1 (including) | 1.6.1 (including) |
Asterisk | Ubuntu | dapper | * |
Asterisk | Ubuntu | intrepid | * |
Asterisk | Ubuntu | jaunty | * |