CVE-2007-2294: Null Pointer Dereference
The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2294?
CVE-2007-2294 has a severity rating that indicates a denial of service vulnerability allowing remote attackers to cause crashes.
How do I fix CVE-2007-2294?
To fix CVE-2007-2294, upgrade Asterisk to a version that is not vulnerable, specifically 1.2.18 or 1.4.3 and later.
Which Asterisk versions are affected by CVE-2007-2294?
CVE-2007-2294 affects Asterisk versions prior to 1.2.18 and all versions in the 1.4.x branch before 1.4.3.
What type of attack exploits CVE-2007-2294?
CVE-2007-2294 can be exploited through a remote denial of service attack using MD5 authentication without a defined password.
Is it possible to mitigate CVE-2007-2294?
Mitigation for CVE-2007-2294 involves disabling the Manager Interface or implementing strong password policies until the software can be upgraded.