CVE-2007-1595
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2007
Last modified:
09/04/2025
Description
The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:asterisk:asterisk:1.2.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.digium.com/view.php?id=9316
- http://secunia.com/advisories/24694
- http://secunia.com/advisories/25582
- http://svn.digium.com/view/asterisk?rev=59073&view=rev
- http://www.novell.com/linux/security/advisories/2007_34_asterisk.html
- http://www.securityfocus.com/bid/23155
- http://www.vupen.com/english/advisories/2007/1123
- http://bugs.digium.com/view.php?id=9316
- http://secunia.com/advisories/24694
- http://secunia.com/advisories/25582
- http://svn.digium.com/view/asterisk?rev=59073&view=rev
- http://www.novell.com/linux/security/advisories/2007_34_asterisk.html
- http://www.securityfocus.com/bid/23155
- http://www.vupen.com/english/advisories/2007/1123



