Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2007-3762

Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.

  • Published: Jul 18, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-3762
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9.3
  • AV:N/AC:M/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
asterisk / asterisk 1.0.11 1.0.11.x
asterisk / asterisk 1.2.14 1.2.14.x
asterisk / asterisk 1.2.16 1.2.16.x
asterisk / asterisk 1.2.5 1.2.5.x
asterisk / asterisk b.1.3.3 b.1.3.3.x
asterisk / asterisknow beta_6 beta_6.x
asterisk / asterisk 1.0.8 1.0.8.x
asterisk / asterisknow beta_5 beta_5.x
asterisk / asterisk 1.4_beta 1.4_beta.x
asterisk / asterisk 1.2.6 1.2.6.x
asterisk / asterisk 1.2.7 1.2.7.x
asterisk / asterisk 1.2.0_beta1 1.2.0_beta1.x
asterisk / asterisk 1.0.12 1.0.12.x
asterisk / asterisk b.2.2.0 b.2.2.0.x
asterisk / asterisk 1.2.8 1.2.8.x
asterisk / asterisk 1.4.2 1.4.2.x
asterisk / asterisk 1.2.15 1.2.15.x
asterisk / asterisk_appliance_developer_kit - 0.4.x
asterisk / asterisk 1.2.17 1.2.17.x
asterisk / asterisk 1.2.11 1.2.11.x
asterisk / asterisk 1.2.12 1.2.12.x
asterisk / asterisk 1.0.6 1.0.6.x
asterisk / asterisk 1.0.9 1.0.9.x
asterisk / asterisk b.1.3.2 b.1.3.2.x
asterisk / asterisk 1.2.10 1.2.10.x
asterisk / asterisk 1.2.9 1.2.9.x
asterisk / asterisk 1.0.7 1.0.7.x
asterisk / asterisk 1.2.13 1.2.13.x
asterisk / asterisk 1.2.0_beta2 1.2.0_beta2.x
asterisk / asterisk 1.0 1.0.x
asterisk / asterisk 1.4.1 1.4.1.x
asterisk / asterisk 1.4.4_2007-04-27 1.4.4_2007-04-27.x
asterisk / asterisk 1.0.10 1.0.10.x
asterisk / asterisk a a.x
asterisk / s800i_appliance 1.0 1.0.x
asterisk / s800i_appliance 1.0.1 1.0.1.x