vendor:
Asterisk
by:
Unknown
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Asterisk
Affected Version From: Prior to Asterisk Open Source 1.4.3, AsteriskNOW Beta 6, and Asterisk Appliance Developer Kit 0.4.0
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:digium:asterisk
Platforms Tested:
2007
Asterisk multiple remote stack-based buffer-overflow vulnerabilities
Multiple remote stack-based buffer-overflow vulnerabilities in Asterisk allow attackers to execute arbitrary code or cause denial-of-service conditions.
Mitigation:
Upgrade to Asterisk Open Source 1.4.3, AsteriskNOW Beta 6, or Asterisk Appliance Developer Kit 0.4.0 or later. Disable 't38 fax over SIP' in 'sip.conf' if not needed.