CVE-2007-2297: High severity Asterisk Asterisk vulnerability
Published Apr 26, 2007
·Updated
The SIP channel driver (chansip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash).
Affected Software
13 affected components
Asterisk Asterisk=1.2.0_beta1
Asterisk Asterisk=1.2.0_beta2
Asterisk Asterisk=1.2.10
Asterisk Asterisk=1.2.11
Asterisk Asterisk=1.2.12
Asterisk Asterisk=1.2.13
Asterisk Asterisk=1.2.14
Asterisk Asterisk=1.2.15
Asterisk Asterisk=1.2.16
Asterisk Asterisk=1.2.17
Asterisk Asterisk=1.4.1
Asterisk Asterisk=1.4.2
Asterisk Asterisk=1.4_beta
Remediation
Patch Available
Event History
Apr 26, 2007
CVE Published
08:19 PM
Apr 27, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2297?
CVE-2007-2297 has a high severity rating as it allows remote attackers to cause a denial of service by crashing affected systems.
2
How do I fix CVE-2007-2297?
To fix CVE-2007-2297, upgrade Asterisk to version 1.2.18 or later or 1.4.3 or later.
3
Which versions of Asterisk are affected by CVE-2007-2297?
CVE-2007-2297 affects Asterisk versions 1.2.0_beta1 through 1.2.17 and 1.4.1 through 1.4.2.
4
What type of vulnerability is CVE-2007-2297 classified as?
CVE-2007-2297 is classified as a denial of service vulnerability affecting the SIP channel driver in Asterisk.
5
Can CVE-2007-2297 be exploited remotely?
Yes, CVE-2007-2297 can be exploited remotely through malformed SIP UDP packets.