CVE-2007-3765 Information
Feb 14, 2021
cve
Description
The STUN implementation in Asterisk 1.4.x before 1.4.8 AsteriskNOW before beta7 Appliance Developer Kit before 0.5.0 and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.
Reference
http://ftp.digium.com/pub/asa/ASA-2007-017.pdf http://secunia.com/advisories/26099 http://www.securityfocus.com/bid/24950 http://www.securitytracker.com/id?1018407 http://www.vupen.com/english/advisories/2007/2563 https://exchange.xforce.ibmcloud.com/vulnerabilities/35480
Share on: