The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Asterisk |
|
Sangoma |
|
Configuration 1 [-]
|
No data.
References
History
Thu, 15 Aug 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sangoma
Sangoma asterisk |
|
CPEs | cpe:2.3:a:asterisk:open_source:1.6.1:*:*:*:*:*:*:* |
cpe:2.3:a:sangoma:asterisk:1.6.1.4:*:*:*:*:*:*:* cpe:2.3:a:sangoma:asterisk:1.6.1:*:*:*:*:*:*:* |
Vendors & Products |
Sangoma
Sangoma asterisk |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:44:55.999Z
Reserved: 2009-07-07T00:00:00
Link: CVE-2009-2346

No data.

Status : Modified
Published: 2009-09-08T18:30:00.203
Modified: 2024-11-21T01:04:39.463
Link: CVE-2009-2346
