VDB
CVE-2006-2898
CVE-2006-2898
PUBLISHED
CVSS 7.5 HIGH
The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames, which bypasses a length check and leads to a buffer overflow involving negative length check. NOTE: the vendor advisory claims that only a DoS is possible, but the original researcher is reliable.
EPSS 0.32% · 55.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.32%
55.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| digium | asterisk | 1.2.8, 1.0.7, 1.0.8 |
| n/a | n/a | n/a |
Timeline
- Jun 7, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 19, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 1016236 vdb
- DSA-1126 vendor-advisory
- 20899 third-party-advisory
- 20658 third-party-advisory
- asterisk-iax2-videoframe-bo(27045) vdb
- 21222 third-party-advisory
- http://www.asterisk.org/node/95 url
- GLSA-200606-15 vendor-advisory
- 18295 vdb
- 20497 third-party-advisory
- 20060606 Asterisk 1.2.9 and Asterisk 1.0.11 Released - Security Fix mailing-list
- ADV-2006-2181 vdb
- SUSE-SR:2006:015 vendor-advisory
- 20060609 CORE-2006-0330: Asterisk PBX truncated video frame vulnerability mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2006-2898 advisory