Digium Asterisk SIP SDP Header sprop-parameter-sets Buffer Overflow

Strike ID:
E13-52l01
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
25
Year:
2013

Description

This strike exploits a stack buffer overflow vulnerability in Digium Asterisk. The content of the sprop-parameter-sets parameter in an SDP header is copied to a fixed length buffer without validation. Successful exploitation could result in execution of arbitrary code or abnormal termination of the Digium Asterisk, leading to a denial of service condition.

CVE

References

Bid