VDB
CVE-2008-2543
CVE-2008-2543
PUBLISHED
CVSS 5 MEDIUM
The ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and Asterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port that is intended solely for localhost communication, and interprets some TCP application-data fields as addresses of memory to free, which allows remote attackers to cause a denial of service (daemon crash) via crafted TCP packets.
EPSS 1.73% · 82.8th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.73%
82.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| asterisk | asterisk-addons | 1.4.5, 1.2.0, 1.2.1 |
| n/a | n/a | n/a |
Timeline
- Jun 5, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- asterisk-addons-ooh323-dos(42869) vdb
- http://downloads.digium.com/pub/security/AST-2008-009.html url
- 29567 vdb
- 1020202 vdb
- ADV-2008-1747 vdb
- 30555 third-party-advisory
- 20080604 AST-2008-009: (Corrected subject) Remote crash vulnerability in ooh323 channel driver mailing-list
- 20080604 AST-2008-009: AST-2008-007 Cryptographic keys generated by OpenSSL on Debian-based systems compromised mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-2543 advisory