Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2013-2685
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2013-2685

2022-10-0316:15:01
Debian Security Bug Tracker
security-tracker.debian.org
11
stack-based buffer overflow
asterisk open source
remote code execution
h.264
sip
sdp

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.456

Percentile

97.4%

Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) header.

OSVersionArchitecturePackageVersionFilename
Debian11allasterisk< 1:16.28.0~dfsg-0+deb11u4asterisk_1:16.28.0~dfsg-0+deb11u4_all.deb
Debian999allasterisk< 1:20.9.3~dfsg+~cs6.14.60671435-1asterisk_1:20.9.3~dfsg+~cs6.14.60671435-1_all.deb

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.456

Percentile

97.4%