CVE-2007-2488

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/05/2007
Last modified:
09/04/2025

Description

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss of transmitted data, and possibly obtain sensitive information (memory contents) or cause a denial of service (application crash), by sending a frame that lacks a 0 byte.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asterisk:asterisk:*:*:*:*:*:*:*:* 1.4.4_2007-04-27 (including)