>> Asterisk SIP Channel Driver Response Handling Remote Denial of Service Vulnerability
Title : Asterisk SIP Channel Driver Response Handling Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1077 CVE ID : CVE-2007-1594 - CVE-2007-2297
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-22
Technical Description
A vulnerability has been identified in Asterisk, which could be exploited by remote attackers to cause a denial of service. This issue is due to an error in the SIP channel driver that fails to properly handle certain SIP responses (code 0), which could be exploited by remote attackers to crash an affected application, creating a denial of service condition.