Lucene search

K
cve[email protected]CVE-2013-7100
HistoryDec 19, 2013 - 10:55 p.m.

CVE-2013-7100

2013-12-1922:55:04
CWE-119
web.nvd.nist.gov
39
cve-2013-7100
buffer overflow
asterisk open source
remote attack
denial of service
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

Low

0.371 Low

EPSS

Percentile

97.2%

Buffer overflow in the unpacksms16 function in apps/app_sms.c in Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before 10.12.4, and 11.x before 11.6.1; Asterisk with Digiumphones 10.x-digiumphones before 10.12.4-digiumphones; and Certified Asterisk 1.8.x before 1.8.15-cert4 and 11.x before 11.2-cert3 allows remote attackers to cause a denial of service (daemon crash) via a 16-bit SMS message with an odd number of bytes, which triggers an infinite loop.

Affected configurations

NVD
Node
digiumasteriskMatch1.8.17.0
OR
digiumasteriskMatch1.8.17.0rc1
OR
digiumasteriskMatch1.8.17.0rc2
OR
digiumasteriskMatch1.8.17.0rc3
OR
digiumasteriskMatch1.8.18.0
OR
digiumasteriskMatch1.8.18.0rc1
OR
digiumasteriskMatch1.8.18.1
OR
digiumasteriskMatch1.8.19.0
OR
digiumasteriskMatch1.8.19.0rc1
OR
digiumasteriskMatch1.8.19.0rc3
OR
digiumasteriskMatch1.8.19.1
OR
digiumasteriskMatch1.8.20.0
OR
digiumasteriskMatch1.8.20.0rc1
OR
digiumasteriskMatch1.8.20.0rc2
OR
digiumasteriskMatch1.8.21.0rc1
OR
digiumasteriskMatch1.8.21.0rc2
OR
digiumasteriskMatch1.8.22.0
OR
digiumasteriskMatch1.8.22.0rc1
OR
digiumasteriskMatch1.8.22.0rc2
OR
digiumasteriskMatch1.8.23.0
OR
digiumasteriskMatch1.8.23.0rc1
OR
digiumasteriskMatch1.8.23.0rc2
OR
digiumasteriskMatch10.10.0
OR
digiumasteriskMatch10.10.0rc1
OR
digiumasteriskMatch10.10.0rc2
OR
digiumasteriskMatch10.11.0
OR
digiumasteriskMatch10.11.0rc1
OR
digiumasteriskMatch10.11.0rc2
OR
digiumasteriskMatch10.11.0rc3
OR
digiumasteriskMatch10.12.0
OR
digiumasteriskMatch10.12.0rc1
OR
digiumasteriskMatch10.12.0rc2
OR
digiumasteriskMatch10.12.1
OR
digiumasteriskMatch10.12.2
OR
digiumasteriskMatch11.0.0
OR
digiumasteriskMatch11.0.0beta1
OR
digiumasteriskMatch11.0.0beta2
OR
digiumasteriskMatch11.0.0rc1
OR
digiumasteriskMatch11.0.0rc2
OR
digiumasteriskMatch11.0.1
OR
digiumasteriskMatch11.0.2
OR
digiumasteriskMatch11.1.0
OR
digiumasteriskMatch11.1.0rc1
OR
digiumasteriskMatch11.1.0rc3
OR
digiumasteriskMatch11.1.1
OR
digiumasteriskMatch11.1.2
OR
digiumasteriskMatch11.2.0rc1
OR
digiumasteriskMatch11.2.0rc2
OR
digiumasteriskMatch11.3.0rc1
OR
digiumasteriskMatch11.3.0rc2
OR
digiumasteriskMatch11.4.0
OR
digiumasteriskMatch11.4.0rc1
OR
digiumasteriskMatch11.4.0rc2
OR
digiumasteriskMatch11.4.0rc3
OR
digiumasteriskMatch11.5.0
OR
digiumasteriskMatch11.5.0rc1
OR
digiumasteriskMatch11.5.0rc2
OR
digiumasteriskMatch11.5.1
OR
digiumasterisk_digiumphonesMatch10.0.0
OR
digiumasterisk_digiumphonesMatch10.0.0rc1
OR
digiumasterisk_digiumphonesMatch10.0.0rc2
OR
digiumasterisk_digiumphonesMatch10.11.0
OR
digiumasterisk_digiumphonesMatch10.11.0rc1
OR
digiumasterisk_digiumphonesMatch10.11.0rc2
OR
digiumasterisk_digiumphonesMatch10.11.0rc3
OR
digiumasterisk_digiumphonesMatch10.12.0
OR
digiumasterisk_digiumphonesMatch10.12.0rc1
OR
digiumasterisk_digiumphonesMatch10.12.0rc2
OR
digiumasterisk_digiumphonesMatch10.12.1
OR
digiumasterisk_digiumphonesMatch10.12.2
OR
digiumcertified_asteriskMatch1.8.15
OR
digiumcertified_asteriskMatch1.8.15cert1
OR
digiumcertified_asteriskMatch1.8.15cert1-rc1
OR
digiumcertified_asteriskMatch1.8.15cert1-rc2
OR
digiumcertified_asteriskMatch1.8.15cert1-rc3
OR
digiumcertified_asteriskMatch1.8.15cert2
OR
digiumcertified_asteriskMatch1.8.15rc1
OR
digiumcertified_asteriskMatch11.2.0
OR
digiumcertified_asteriskMatch11.2.0cert1
OR
digiumcertified_asteriskMatch11.2.0rc1
OR
digiumcertified_asteriskMatch11.2.0rc2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

Low

0.371 Low

EPSS

Percentile

97.2%