CVE-2006-4345: Buffer Overflow
Published Aug 24, 2006
·Updated
Stack-based buffer overflow in channels/chanmgcp.c in MGCP in Asterisk 1.0 through 1.2.10 allows remote attackers to execute arbitrary code via a crafted audit endpoint (AUEP) response.
Affected Software
20 affected components
Asterisk=1.0.0
Asterisk=1.0.1
Asterisk=1.0.2
Asterisk=1.0.3
Asterisk=1.0.4
Asterisk=1.0.5
Asterisk=1.0.6
Asterisk=1.0.7
Asterisk=1.0.8
Asterisk=1.0.9
Asterisk=1.0.10
Asterisk=1.0_rc1
Asterisk=1.0_rc2
Asterisk=1.2.0_beta1
Asterisk=1.2.0_beta2
Asterisk=1.2.6
Asterisk=1.2.7
Asterisk=1.2.8
Asterisk=1.2.9
Asterisk=1.2.10
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Aug 24, 2006
CVE Published
08:04 PM
Aug 25, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4345?
CVE-2006-4345 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2006-4345?
Fix CVE-2006-4345 by upgrading to Asterisk version 1.2.11 or higher.
3
What software versions are affected by CVE-2006-4345?
CVE-2006-4345 affects Asterisk versions 1.0.0 to 1.2.10.
4
Can CVE-2006-4345 be exploited remotely?
Yes, CVE-2006-4345 can be exploited remotely by sending a crafted audit endpoint response.
5
What type of vulnerability is CVE-2006-4345?
CVE-2006-4345 is a stack-based buffer overflow vulnerability.