← Back

CVE-2008-1923

nvd nist
Published: Apr 23, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:C
Exploitability: 8.6 / Impact: 6.9
Source: NVD

Description

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

Affected (137)

5 products
Asterisk Appliance Developer Kit
Asterisk Business Edition
Asterisknow
Open Source
S800i
Configuration A
137 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Asterisk
Up to b2.5.1
Up to c1.8.0
Version a
Version b.1.3.2
Version b.1.3.3
Version b.2.2.0
Version b.2.2.1
Version b.2.3.1
Version b.2.3.2
Version b.2.3.3
Version b.2.3.4
Version b.2.5.0
Version c.1.0-beta7
Version c.1.0-beta8
Version c.1.0beta7
Version c.1.6.1
Asterisk
Up to 1.0.2
Version 1.0.1
Version 1.0
Asterisk
Version 1.0.0
Version 1.0.11.1
Version 1.0.11
Version 1.0.12
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.0
Version 1.2.0
Version 1.2.10
Version 1.2.10 netsec
Version 1.2.11
Version 1.2.11 netsec
Version 1.2.12.1
Version 1.2.12
Version 1.2.12 netsec
Version 1.2.13
Version 1.2.13 netsec
Version 1.2.14
Version 1.2.14 netsec
Version 1.2.15
Version 1.2.15 netsec
Version 1.2.16
Version 1.2.16 netsec
Version 1.2.17
Version 1.2.17 netsec
Version 1.2.18
Version 1.2.18 netsec
Version 1.2.19
Version 1.2.19 netsec
Version 1.2.1
Version 1.2.20
Version 1.2.20 netsec
Version 1.2.21.1
Version 1.2.21.1 netsec
Version 1.2.21
Version 1.2.21 netsec
Version 1.2.22
Version 1.2.22 netsec
Version 1.2.23
Version 1.2.23 netsec
Version 1.2.24
Version 1.2.24 netsec
Version 1.2.25
Version 1.2.25 netsec
Version 1.2.26.1
Version 1.2.26.1 netsec
Version 1.2.26.2
Version 1.2.26.2 netsec
Version 1.2.26
Version 1.2.26 netsec
Version 1.2.27
Version 1.2.28
Version 1.2.2
Version 1.2.3
Version 1.2.3 netsec
Version 1.2.4
Version 1.2.4 netsec
Version 1.2.5
Version 1.2.5 netsec
Version 1.2.6
Version 1.2.6 netsec
Version 1.2.7.1
Version 1.2.7.1 netsec
Version 1.2.7
Version 1.2.7 netsec
Version 1.2.8
Version 1.2.8 netsec
Version 1.2.9.1
Version 1.2.9.1 netsec
Version 1.2.9
Version 1.4.0
Version 1.4.0 beta2
Version 1.4.0 beta3
Version 1.4.0 beta4
Version 1.4.10.1
Version 1.4.10
Version 1.4.11
Version 1.4.12.1
Version 1.4.12
Version 1.4.13
Version 1.4.14
Version 1.4.15
Version 1.4.16.1
Version 1.4.16.2
Version 1.4.16
Version 1.4.17
Version 1.4.18.1
Version 1.4.18
Version 1.4.19 rc1
Version 1.4.19 rc2
Version 1.4.19 rc3
Version 1.4.19 rc4
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7.1
Version 1.4.7
Version 1.4.8
Version 1.4.9
Asterisk
Up to 1.1.0.2
Version 1.0.1
Version 1.0.2
Version 1.0.3.3
Version 1.0.3
Version 1.0
Version 1.1.0.1
Version 1.1.0

Related CWEs

Timeline

No history available yet.