CVE-2007-3762: Buffer Overflow
Stack-based buffer overflow in the IAX2 channel driver (chaniax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3762?
CVE-2007-3762 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I mitigate CVE-2007-3762?
To mitigate CVE-2007-3762, you should upgrade to Asterisk version 1.2.22, 1.4.8, Business Edition B.2.2.1, or later.
What versions of Asterisk are affected by CVE-2007-3762?
CVE-2007-3762 affects Asterisk versions prior to 1.2.22 and 1.4.x before 1.4.8.
Can CVE-2007-3762 be exploited remotely?
Yes, CVE-2007-3762 allows remote attackers to exploit the vulnerability via specially crafted messages.
What is the nature of the vulnerability in CVE-2007-3762?
CVE-2007-3762 involves a stack-based buffer overflow in the IAX2 channel driver (chan_iax2) of Asterisk.