Lucene search

K
cve[email protected]CVE-2007-5358
HistoryOct 12, 2007 - 11:17 p.m.

CVE-2007-5358

2007-10-1223:17:00
CWE-119
web.nvd.nist.gov
105
cve-2007-5358
buffer overflow
voicemail
asterisk
remote code execution
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%

Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files.

Affected configurations

NVD
Node
digiumasteriskRange1.4.12
CPENameOperatorVersion
digium:asteriskdigium asteriskle1.4.12

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%