Digium Asterisk Skinny Channel Keypad Button Message Heap Buffer Overflow

Strike ID:
E12-4v301
CVSS:
6.5 (AV:N/AC:L/Au:S/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2012

Description

This strike exploits a heap buffer overflow vulnerability in Digium Asterisk. The program fails to check the number of KEYPAD_BUTTON_MESSAGE messages sent and will write them to a fixed length buffer. Successful exploitation can result in execution of arbitrary code or abnormal termination of the program, resulting in a denial of service condition.

CVE

References

Bid