Out-of-Bounds Affecting asterisk package, versions [,1.2.35)[1.3.0.0,1.3.0.3)[1.4.26.0,1.4.26.2)[1.6.0.0,1.6.0.15)[1.6.1.0,1.6.1.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
71.45% (99th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ASTERISK-2371595
  • published26 Jan 2022
  • disclosed8 Sept 2009
  • creditUnknown

Introduced: 8 Sep 2009

CVE-2009-2346  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade asterisk to version 1.2.35, 1.3.0.3, 1.4.26.2, 1.6.0.15, 1.6.1.6 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-Bounds. The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.

CVSS Base Scores

version 3.1