CVE-2013-7100: Buffer Overflow
Buffer overflow in the unpacksms16 function in apps/appsms.c in Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before 10.12.4, and 11.x before 11.6.1; Asterisk with Digiumphones 10.x-digiumphones before 10.12.4-digiumphones; and Certified Asterisk 1.8.x before 1.8.15-cert4 and 11.x before 11.2-cert3 allows remote attackers to cause a denial of service (daemon crash) via a 16-bit SMS message with an odd number of bytes, which triggers an infinite loop.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7100?
CVE-2013-7100 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2013-7100?
To fix CVE-2013-7100, update Asterisk to the latest version that addresses this vulnerability.
Which versions of Asterisk are affected by CVE-2013-7100?
CVE-2013-7100 affects Asterisk versions 1.8.x before 1.8.24.1, 10.x before 10.12.4, and 11.x before 11.6.1.
What is the cause of CVE-2013-7100?
CVE-2013-7100 is caused by a buffer overflow in the unpacksms16 function in the Asterisk code.
Is there a workaround for CVE-2013-7100?
There are no official workarounds for CVE-2013-7100; updating to a patched version is the recommended approach.