CVE-2006-2898
Published Jun 7, 2006
Last updated 6 years ago
Overview
- Description
- The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames, which bypasses a length check and leads to a buffer overflow involving negative length check. NOTE: the vendor advisory claims that only a DoS is possible, but the original researcher is reliable.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Evaluator
- Comment
- -
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:digium:asterisk:1.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46C60C04-EF59-4F5C-96E5-A6E693EA9A06" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3636BB44-DF4D-40AB-8EBB-1EC5D911E4A2" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3B3C254-29D9-4911-89A9-AC0CD9EB13F0" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D8679FD-B2E5-46F6-B20C-F109B9706C63" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.2.0_beta1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4042CC21-F3CB-4C77-9E60-AF8AA9A191C7" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.2.0_beta2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C656168D-7D6A-4E84-9196-A8B170E1F7CF" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C619138A-557F-419E-9832-D0FB0E9042C9" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6656EA0-4D4F-4251-A30F-48375C5CE3E0" }, { "criteria": "cpe:2.3:a:digium:asterisk:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AAD9104-BA4A-478F-9B56-195E0F9A7DF5" } ], "operator": "OR" } ] } ]