CVE-2007-3765
The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN…
Does this matter?
Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.
Description
The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- asterisk/asterisk · asterisk/asterisk appliance developer kit · asterisk/asterisknow · asterisk/s800i appliance
- Source
- cve@mitre.org
References
- http://ftp.digium.com/pub/asa/ASA-2007-017.pdfPatch, Vendor Advisory
- http://secunia.com/advisories/26099
- http://www.securityfocus.com/bid/24950
- http://www.securitytracker.com/id?1018407
- http://www.vupen.com/english/advisories/2007/2563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35480
- http://ftp.digium.com/pub/asa/ASA-2007-017.pdfPatch, Vendor Advisory
- http://secunia.com/advisories/26099
- http://www.securityfocus.com/bid/24950
- http://www.securitytracker.com/id?1018407
- http://www.vupen.com/english/advisories/2007/2563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35480
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.