← Back

CVE-2007-3763

nvd nist
Published: Jul 18, 2007Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.

Affected (36)

4 products
Asterisk
Asterisk Appliance Developer Kit
Asterisknow
S800i Appliance
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Asterisk
Version 1.0.10
Version 1.0.11
Version 1.0.12
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.0
Version 1.2.0_beta1
Version 1.2.0_beta2
Version 1.2.10
Version 1.2.11
Version 1.2.12
Version 1.2.13
Version 1.2.14
Version 1.2.15
Version 1.2.16
Version 1.2.17
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9
Version 1.4.1
Version 1.4.2
Version 1.4.4_2007-04-27
Version 1.4_beta
Version a
Version b.1.3.2
Version b.1.3.3
Version b.2.2.0
Up to 0.4
Asterisk
Version beta_5
Version beta_6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Asterisk
Version 1.0.1
Version 1.0

References (20)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.