>> Asterisk Products Skinny Channel Driver Remote Denial of Service Vulnerability
Title : Asterisk Products Skinny Channel Driver Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-2808 CVE ID : CVE-2007-4280
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-08
Technical Description
A vulnerability has been identified in various Asterisk products, which could be exploited by remote attackers to cause a denial of service. This issue is caused by an error in the Skinny channel driver (chan_skinny) when processing a "CAPABILITIES_RES_MESSAGE" packet with a capabilities count greater than the total number of items in the "capabilities_res_message" array, which could be exploited by remote authenticated attackers to crash a vulnerable application, creating a denial of service condition.