Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-2898
HistoryJun 07, 2006 - 12:00 a.m.

CVE-2006-2898

2006-06-0700:00:00
ubuntu.com
ubuntu.com
11

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.149 Low

EPSS

Percentile

95.8%

The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and
1.0.x before 1.0.11 allows remote attackers to cause a denial of service
(crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames,
which bypasses a length check and leads to a buffer overflow involving
negative length check. NOTE: the vendor advisory claims that only a DoS is
possible, but the original researcher is reliable.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchasterisk< 1.2.7.1.dfsg-2ubuntu3.4UNKNOWN
ubuntu6.10noarchasterisk< 1.2.12.1.dfsg-1ubuntu1.4UNKNOWN
ubuntu7.04noarchasterisk< 1.2.16~dfsg-1ubuntu3.1UNKNOWN
ubuntu7.10noarchasterisk< 1.4.11~dfsg-1UNKNOWN
ubuntu8.04noarchasterisk< 1.4.11~dfsg-1UNKNOWN
ubuntu8.10noarchasterisk< 1.4.11~dfsg-1UNKNOWN
ubuntu9.04noarchasterisk< 1.4.11~dfsg-1UNKNOWN
ubuntu9.10noarchasterisk< 1.4.11~dfsg-1UNKNOWN
ubuntu6.10noarchzaptel< 1.2.8.dfsg-1UNKNOWN
ubuntu7.04noarchzaptel< 1.2.8.dfsg-1UNKNOWN
Rows per page:
1-10 of 151

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.149 Low

EPSS

Percentile

95.8%