CVE-2007-3763: Null Pointer Dereference
The IAX2 channel driver (chaniax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3763?
The severity of CVE-2007-3763 is considered critical due to its ability to cause a denial of service.
How do I fix CVE-2007-3763?
To fix CVE-2007-3763, upgrade to Asterisk version 1.2.22, 1.4.8 or later, or apply relevant patches.
What software is affected by CVE-2007-3763?
CVE-2007-3763 affects multiple versions of Asterisk, including versions before 1.2.22 and certain Business Edition and AsteriskNOW versions.
What types of attacks are possible with CVE-2007-3763?
CVE-2007-3763 allows remote attackers to perform denial of service attacks by exploiting crafted requests.
Which Asterisk versions should be avoided due to CVE-2007-3763?
Asterisk versions 1.0.x, 1.2.x, and any versions prior to 1.2.22 should be avoided due to vulnerabilities associated with CVE-2007-3763.