CVE-2007-2488

Priority
Description
The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not
properly null terminate data, which allows remote attackers to trigger loss
of transmitted data, and possibly obtain sensitive information (memory
contents) or cause a denial of service (application crash), by sending a
frame that lacks a 0 byte.
Package
Upstream:needs-triage
More Information

Updated: 2019-03-19 11:42:20 UTC (commit 15472795df7e9de45b82f2d36b8b419b939f97b2)