Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/28308 | vdb entry exploit |
http://securityreason.com/securityalert/3763 | third party advisory |
http://labs.musecurity.com/advisories/MU-200803-01.txt | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41305 | vdb entry |
http://securitytracker.com/id?1019628 | vdb entry |
http://secunia.com/advisories/29426 | third party advisory vendor advisory |
http://www.asterisk.org/node/48466 | |
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00438.html | vendor advisory |
http://www.securityfocus.com/archive/1/489817/100/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2008/0928 | vdb entry |
http://downloads.digium.com/pub/security/AST-2008-002.html | |
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00514.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41302 | vdb entry |
http://secunia.com/advisories/29470 | third party advisory |