CVE-2007-4521: Medium severity Asterisk Asterisk vulnerability
Published Aug 28, 2007
·Updated
Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient listens to voicemail.
Affected Software
7 affected components
Asterisk Asterisk=1.4.5
Asterisk Asterisk=1.4.6
Asterisk Asterisk=1.4.7
Asterisk Asterisk=1.4.8
Asterisk Asterisk=1.4.9
Asterisk Asterisk=1.4.10
Asterisk Asterisk=1.4.11
Event History
Aug 28, 2007
CVE Published
01:17 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4521?
CVE-2007-4521 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-4521?
To mitigate CVE-2007-4521, upgrade Asterisk to version 1.4.12 or later.
3
Which versions of Asterisk are affected by CVE-2007-4521?
CVE-2007-4521 affects Asterisk versions 1.4.5 through 1.4.11.
4
What happens if I don't address CVE-2007-4521?
Failure to address CVE-2007-4521 may allow remote attackers to crash the voicemail service.
5
Who is impacted by CVE-2007-4521?
Organizations using Asterisk versions 1.4.5 to 1.4.11 with IMAP voicemail storage are impacted by CVE-2007-4521.