7.5
CVSSv2

CVE-2006-2898

Published: 07/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x prior to 1.2.9 and 1.0.x prior to 1.0.11 allows remote malicious users to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames, which bypasses a length check and leads to a buffer overflow involving negative length check. NOTE: the vendor advisory claims that only a DoS is possible, but the original researcher is reliable.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.2.0_beta1

digium asterisk 1.2.0_beta2

digium asterisk 1.0.10

digium asterisk 1.0.7

digium asterisk 1.2.8

digium asterisk 1.2.6

digium asterisk 1.2.7

digium asterisk 1.0.8

digium asterisk 1.0.9

Vendor Advisories

Debian Bug report logs - #380054 CVE-2006-2898: Denial of service in Asterisk Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Martin Schulze <joey@infodromorg> Date: Thu, 27 Jul 2006 ...