PoC Index

CVE-2007-2293

HIGH 7.6EPSS 23.9%

Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.

CVSS v2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
23.88% chance of exploitation in the next 30 days, 98th percentile
Published
2007-04-26
Updated
2024-08-07

ExploitDB entries (2)

References

Related