CVE-2009-2346
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
08/09/2009
Last modified:
09/04/2025
Description
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:asterisk:asterisk:b.1.3.2:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.1.3.3:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.2.0:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.2.1:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.3.1:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.3.2:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.3.3:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.3.4:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.3.5:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.3.6:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.5.1:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.5.3:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.5.4:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.5.5:*:business:*:*:*:*:* | ||
cpe:2.3:a:asterisk:asterisk:b.2.5.6:*:business:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://downloads.asterisk.org/pub/security/AST-2009-006.html
- http://secunia.com/advisories/36593
- http://securitytracker.com/id?1022819=
- http://www.securityfocus.com/archive/1/506257/100/0/threaded
- http://www.securityfocus.com/bid/36275
- http://downloads.asterisk.org/pub/security/AST-2009-006.html
- http://secunia.com/advisories/36593
- http://securitytracker.com/id?1022819=
- http://www.securityfocus.com/archive/1/506257/100/0/threaded
- http://www.securityfocus.com/bid/36275