Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-5358
HistoryOct 12, 2007 - 12:00 a.m.

CVE-2007-5358

2007-10-1200:00:00
ubuntu.com
ubuntu.com
7

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.037 Low

EPSS

Percentile

91.8%

Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x
before 1.4.13, when using IMAP storage, might allow (1) remote attackers to
execute arbitrary code via a long combination of Content-type and
Content-description headers, or (2) local users to execute arbitrary code
via a long combination of astspooldir, voicemail context, and voicemail
mailbox fields. NOTE: vector 2 requires write access to Asterisk
configuration files.

Notes

Author Note
jdstrand 1.4.x only. 1.2 and 1.0 not affected

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.037 Low

EPSS

Percentile

91.8%

Related for UB:CVE-2007-5358