Lucene search

K
nvd[email protected]NVD:CVE-2013-2685
HistoryApr 01, 2013 - 4:55 p.m.

CVE-2013-2685

2013-04-0116:55:03
CWE-119
web.nvd.nist.gov
5

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.456

Percentile

97.4%

Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) header.

Affected configurations

Nvd
Node
asteriskopen_sourceMatch11.0.0
OR
asteriskopen_sourceMatch11.0.0beta1
OR
asteriskopen_sourceMatch11.0.0beta2
OR
asteriskopen_sourceMatch11.0.0rc1
OR
asteriskopen_sourceMatch11.0.0rc2
OR
asteriskopen_sourceMatch11.0.1
OR
asteriskopen_sourceMatch11.0.2
OR
asteriskopen_sourceMatch11.1.0
OR
asteriskopen_sourceMatch11.1.0rc1
OR
asteriskopen_sourceMatch11.1.0rc3
OR
asteriskopen_sourceMatch11.1.1
OR
asteriskopen_sourceMatch11.1.2
OR
asteriskopen_sourceMatch11.2.0
OR
asteriskopen_sourceMatch11.2.0rc1
OR
asteriskopen_sourceMatch11.2.0rc2
OR
asteriskopen_sourceMatch11.2.1

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.456

Percentile

97.4%