>> Asterisk Products IAX2 Channel Driver Remote Denial of Service Vulnerability
Title : Asterisk Products IAX2 Channel Driver Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-2701 CVE ID : CVE-2007-4103
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-30
Technical Description
A vulnerability has been identified in various Asterisk products, which could be exploited by attackers to cause a denial of service. This issue is caused by an error in the IAX2 channel driver (chan_iax2) when processing multiple NEW packets for valid extensions, which could be exploited by remote unauthenticated attackers to exhaust all available memory resources, creating a denial of service condition.