Vector: | Remote |
Severity: | High |
Patch: | Patched |
Impact: | Remote Code Execution (RCE) |
Software: | Asterisk 1.x |
A remote code execution vulnerability was reported in Asterisk SIP Request.
Buffer overflow vulnerability exists in the SIP (Session Initiation Protocol) implementation when handling certain SIP requests. An attacker can exploit this vulnerability by sending a specially crafted SIP request, which causes a buffer overflow.
Solution:
For : The vendor issued an updated CVS version on 15th of August 2003.
Links:
http://www.atstake.com/research/advisories/2003/a090403-1.txt