PublicDate: 2007-04-26 20:19:00 UTC Candidate: CVE-2007-2294 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2294 Description: The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_asterisk: ignored (reached end-of-life) edgy_asterisk: released (1.2.12.1.dfsg-1ubuntu1.4) feisty_asterisk: released (1.2.16~dfsg-1ubuntu3.1) gutsy_asterisk: released (1:1.4.3dfsg-1) hardy_asterisk: released (1:1.4.3dfsg-1) intrepid_asterisk: released (1:1.4.3dfsg-1) jaunty_asterisk: released (1:1.4.3dfsg-1) karmic_asterisk: released (1:1.4.3dfsg-1) devel_asterisk: released (1:1.4.3dfsg-1) upstream_asterisk: released (1.4.3)