CVE-2007-2293
HIGH 7.6EPSS 23.9%
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.
- CVSS v2.0
- 7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C - EPSS
- 23.88% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2007-04-26
- Updated
- 2024-08-07