CVE-2007-3765: Medium severity Asterisk Asterisk vulnerability
The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3765?
CVE-2007-3765 is classified as a denial of service vulnerability affecting Asterisk implementations.
How do I fix CVE-2007-3765?
To fix CVE-2007-3765, update Asterisk to version 1.4.8 or later, or to the appropriate patched versions of AsteriskNOW or the Appliance Developer Kit.
What versions of Asterisk are affected by CVE-2007-3765?
CVE-2007-3765 affects Asterisk versions 1.4.x before 1.4.8 and various versions of AsteriskNOW, Appliance Developer Kit, and s800i before specified versions.
Can CVE-2007-3765 be exploited remotely?
Yes, CVE-2007-3765 can be exploited remotely by sending a crafted STUN packet to an RTP port.
What type of attack does CVE-2007-3765 enable?
CVE-2007-3765 enables a denial of service attack that can cause the targeted Asterisk system to crash.