Lucene search

K
cveMitreCVE-2013-2685
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2013-2685

2022-10-0316:15:01
CWE-119
mitre
web.nvd.nist.gov
117
cve-2013-2685
asterisk
buffer overflow
security
vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

Low

EPSS

0.456

Percentile

97.4%

Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) header.

Affected configurations

Nvd
Node
asteriskopen_sourceMatch11.0.0
OR
asteriskopen_sourceMatch11.0.0beta1
OR
asteriskopen_sourceMatch11.0.0beta2
OR
asteriskopen_sourceMatch11.0.0rc1
OR
asteriskopen_sourceMatch11.0.0rc2
OR
asteriskopen_sourceMatch11.0.1
OR
asteriskopen_sourceMatch11.0.2
OR
asteriskopen_sourceMatch11.1.0
OR
asteriskopen_sourceMatch11.1.0rc1
OR
asteriskopen_sourceMatch11.1.0rc3
OR
asteriskopen_sourceMatch11.1.1
OR
asteriskopen_sourceMatch11.1.2
OR
asteriskopen_sourceMatch11.2.0
OR
asteriskopen_sourceMatch11.2.0rc1
OR
asteriskopen_sourceMatch11.2.0rc2
OR
asteriskopen_sourceMatch11.2.1
VendorProductVersionCPE
asteriskopen_source11.2.0cpe:/a:asterisk:open_source:11.2.0:rc2::
asteriskopen_source11.0.2cpe:/a:asterisk:open_source:11.0.2:::
asteriskopen_source11.1.1cpe:/a:asterisk:open_source:11.1.1:::
asteriskopen_source11.2.0cpe:/a:asterisk:open_source:11.2.0:::
asteriskopen_source11.0.1cpe:/a:asterisk:open_source:11.0.1:::
asteriskopen_source11.0.0cpe:/a:asterisk:open_source:11.0.0:::
asteriskopen_source11.2.0cpe:/a:asterisk:open_source:11.2.0:rc1::
asteriskopen_source11.1.0cpe:/a:asterisk:open_source:11.1.0:rc3::
asteriskopen_source11.1.0cpe:/a:asterisk:open_source:11.1.0:rc1::
asteriskopen_source11.0.0cpe:/a:asterisk:open_source:11.0.0:rc1::
Rows per page:
1-10 of 161

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

Low

EPSS

0.456

Percentile

97.4%