CVE-2007-4455

Publication date 22 August 2007

Last updated 24 July 2024


Ubuntu priority

The SIP channel driver (chan_sip) in Asterisk Open Source 1.4.x before 1.4.11, AsteriskNOW before beta7, Asterisk Appliance Developer Kit 0.x before 0.8.0, and s800i (Asterisk Appliance) 1.x before 1.0.3 allows remote attackers to cause a denial of service (memory exhaustion) via a SIP dialog that causes a large number of history entries to be created.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
asterisk 9.10 karmic
Fixed 1:1.4.11~dfsg-1
9.04 jaunty
Fixed 1:1.4.11~dfsg-1
8.10 intrepid
Fixed 1:1.4.11~dfsg-1
8.04 LTS hardy
Fixed 1:1.4.11~dfsg-1
7.10 gutsy
Fixed 1:1.4.11~dfsg-1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life