CVE-2007-1561: High severity Asterisk Asterisk vulnerability
Published Mar 21, 2007
·Updated
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.
Affected Software
4 affected components
Asterisk Asterisk=1.2.14
Asterisk Asterisk=1.2.15
Asterisk Asterisk=1.2.16
Asterisk Asterisk=1.4.1
Remediation
Patch Available
Event History
Mar 21, 2007
CVE Published
07:19 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1561?
CVE-2007-1561 has a severity rating that indicates it can lead to a denial of service due to crashes in the affected Asterisk versions.
2
How do I fix CVE-2007-1561?
To fix CVE-2007-1561, upgrade Asterisk to version 1.2.17 or 1.4.2 or later.
3
Which versions of Asterisk are affected by CVE-2007-1561?
Asterisk versions 1.2.14, 1.2.15, 1.2.16, and 1.4.1 are affected by CVE-2007-1561.
4
What type of attack does CVE-2007-1561 exploit?
CVE-2007-1561 can be exploited by sending specially crafted SIP INVITE messages containing both valid and invalid IP addresses.
5
What impact does CVE-2007-1561 have on Asterisk servers?
CVE-2007-1561 can cause Asterisk servers to crash, leading to service disruptions.