CVE-2007-5358
Publication date 12 October 2007
Last updated 24 July 2024
Ubuntu priority
Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files.
Status
Package | Ubuntu Release | Status |
---|---|---|
asterisk | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty |
Not affected
|
|
6.10 edgy |
Not affected
|
|
6.06 LTS dapper |
Not affected
|