CVE-2008-1923
N/A
N/A
Summary
The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42049
- http://downloads.digium.com/pub/security/AST-2008-006.html
- http://bugs.digium.com/view.php?id=10078
- http://www.altsci.com/concepts/page.php?s=asteri&p=1
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42049
- http://downloads.digium.com/pub/security/AST-2008-006.html
- http://bugs.digium.com/view.php?id=10078
- http://www.altsci.com/concepts/page.php?s=asteri&p=1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.