Lucene search

K
cveMitreCVE-2008-1289
HistoryMar 24, 2008 - 5:44 p.m.

CVE-2008-1289

2008-03-2417:44:00
CWE-119
mitre
web.nvd.nist.gov
33
asterisk
buffer overflow
security vulnerability
remote attack
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.97

Percentile

99.7%

Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.

Affected configurations

Nvd
Node
asteriskasterisk_appliance_developer_kitMatch1.4
OR
asteriskasterisk_business_editionRange≀c.1.0-beta8
OR
asteriskasterisk_business_editionRange≀c.1.0beta7
OR
asteriskasterisknowRange≀1.0.1
OR
asteriskopen_sourceRange≀1.4.18
OR
asteriskopen_sourceRange≀1.4.19rc-2
OR
asteriskopen_sourceRange≀1.6.0_beta5
OR
asterisks800iRange≀1.1.0.1
VendorProductVersionCPE
asteriskasterisk_appliance_developer_kit1.4cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:1.4:*:*:*:*:*:*:*
asteriskasterisk_business_edition*cpe:2.3:a:asterisk:asterisk_business_edition:*:*:*:*:*:*:*:*
asteriskasterisknow*cpe:2.3:a:asterisk:asterisknow:*:*:*:*:*:*:*:*
asteriskopen_source*cpe:2.3:a:asterisk:open_source:*:*:*:*:*:*:*:*
asteriskopen_source*cpe:2.3:a:asterisk:open_source:*:rc-2:*:*:*:*:*:*
asterisks800i*cpe:2.3:a:asterisk:s800i:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.97

Percentile

99.7%