7.5
CVSSv2

CVE-2006-2898

Published: 07/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x prior to 1.2.9 and 1.0.x prior to 1.0.11 allows remote malicious users to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames, which bypasses a length check and leads to a buffer overflow involving negative length check. NOTE: the vendor advisory claims that only a DoS is possible, but the original researcher is reliable.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.2.0 beta1

digium asterisk 1.0.9

digium asterisk 1.0.10

digium asterisk 1.2.8

digium asterisk 1.2.6

digium asterisk 1.0.8

digium asterisk 1.2.7

digium asterisk 1.2.0 beta2

digium asterisk 1.0.7

Vendor Advisories

Debian Bug report logs - #380054 CVE-2006-2898: Denial of service in Asterisk Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Martin Schulze <joey@infodromorg> Date: Thu, 27 Jul 2006 ...