← All CVEs

CVE-2007-2293

high · 7.6

Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.

7.6
CVSS
23.9%
EPSS (exploit prob.)
98th
EPSS percentile
2007-04-26
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
asteriskasterisk1.4.1
asteriskasterisk1.4.2
asteriskasterisk1.4_beta

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2293