7.8

CVE-2009-2346

The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.

Data is provided by the National Vulnerability Database (NVD)
AsteriskAsterisk Versionb.1.3.2 Editionbusiness
AsteriskAsterisk Versionb.1.3.3 Editionbusiness
AsteriskAsterisk Versionb.2.2.0 Editionbusiness
AsteriskAsterisk Versionb.2.2.1 Editionbusiness
AsteriskAsterisk Versionb.2.3.1 Editionbusiness
AsteriskAsterisk Versionb.2.3.2 Editionbusiness
AsteriskAsterisk Versionb.2.3.3 Editionbusiness
AsteriskAsterisk Versionb.2.3.4 Editionbusiness
AsteriskAsterisk Versionb.2.3.5 Editionbusiness
AsteriskAsterisk Versionb.2.3.6 Editionbusiness
AsteriskAsterisk Versionb.2.5.1 Editionbusiness
AsteriskAsterisk Versionb.2.5.3 Editionbusiness
AsteriskAsterisk Versionb.2.5.4 Editionbusiness
AsteriskAsterisk Versionb.2.5.5 Editionbusiness
AsteriskAsterisk Versionb.2.5.6 Editionbusiness
AsteriskAsterisk Versionb.2.5.8 Editionbusiness
AsteriskAsterisk Versionb.2.5.9 Editionbusiness
AsteriskAsterisk Versionc.1.0_beta7 Editionbusiness
AsteriskAsterisk Versionc.1.0_beta8 Editionbusiness
AsteriskAsterisk Versionc.1.6 Editionbusiness
AsteriskAsterisk Versionc.1.6.1 Editionbusiness
AsteriskAsterisk Versionc.1.6.2 Editionbusiness
AsteriskAsterisk Versionc.1.8.1 Editionbusiness
AsteriskAsterisk Versionc.1.10.3 Editionbusiness
AsteriskAsterisk Versionc.1.10.4 Editionbusiness
AsteriskAsterisk Versionc.1.10.5 Editionbusiness
AsteriskAsterisk Versionc.2.1.2.1 Editionbusiness
AsteriskAsterisk Versionc.2.3 Editionbusiness
AsteriskAsterisk Versionc.2.3.3 Editionbusiness
AsteriskAsterisk Versionc.2.4.2 Editionbusiness
AsteriskAsterisk Versionc.3.1.0 Editionbusiness
AsteriskOpen Source Version1.2.0
AsteriskOpen Source Version1.2.0 Updatebeta1
AsteriskOpen Source Version1.2.0 Updatebeta2
AsteriskOpen Source Version1.2.0 Updaterc1
AsteriskOpen Source Version1.2.0 Updaterc2
AsteriskOpen Source Version1.2.1
AsteriskOpen Source Version1.2.2
AsteriskOpen Source Version1.2.2 Updatenetsec
AsteriskOpen Source Version1.2.3
AsteriskOpen Source Version1.2.3 Updatenetsec
AsteriskOpen Source Version1.2.4
AsteriskOpen Source Version1.2.4 Updatenetsec
AsteriskOpen Source Version1.2.5
AsteriskOpen Source Version1.2.5 Updatenetsec
AsteriskOpen Source Version1.2.6
AsteriskOpen Source Version1.2.6 Updatenetsec
AsteriskOpen Source Version1.2.7
AsteriskOpen Source Version1.2.7 Updatenetsec
AsteriskOpen Source Version1.2.7.1
AsteriskOpen Source Version1.2.7.1 Updatenetsec
AsteriskOpen Source Version1.2.8
AsteriskOpen Source Version1.2.8 Updatenetsec
AsteriskOpen Source Version1.2.9
AsteriskOpen Source Version1.2.9.1
AsteriskOpen Source Version1.2.9.1 Updatenetsec
AsteriskOpen Source Version1.2.10
AsteriskOpen Source Version1.2.10 Updatenetsec
AsteriskOpen Source Version1.2.11
AsteriskOpen Source Version1.2.11 Updatenetsec
AsteriskOpen Source Version1.2.12
AsteriskOpen Source Version1.2.12 Updatenetsec
AsteriskOpen Source Version1.2.12.1
AsteriskOpen Source Version1.2.12.1 Updatenetsec
AsteriskOpen Source Version1.2.13
AsteriskOpen Source Version1.2.13 Updatenetsec
AsteriskOpen Source Version1.2.14
AsteriskOpen Source Version1.2.14 Updatenetsec
AsteriskOpen Source Version1.2.15
AsteriskOpen Source Version1.2.15 Updatenetsec
AsteriskOpen Source Version1.2.16
AsteriskOpen Source Version1.2.16 Updatenetsec
AsteriskOpen Source Version1.2.17
AsteriskOpen Source Version1.2.17 Updatenetsec
AsteriskOpen Source Version1.2.18
AsteriskOpen Source Version1.2.18 Updatenetsec
AsteriskOpen Source Version1.2.19
AsteriskOpen Source Version1.2.19 Updatenetsec
AsteriskOpen Source Version1.2.20
AsteriskOpen Source Version1.2.20 Updatenetsec
AsteriskOpen Source Version1.2.21
AsteriskOpen Source Version1.2.21 Updatenetsec
AsteriskOpen Source Version1.2.21.1
AsteriskOpen Source Version1.2.21.1 Updatenetsec
AsteriskOpen Source Version1.2.22
AsteriskOpen Source Version1.2.22 Updatenetsec
AsteriskOpen Source Version1.2.23
AsteriskOpen Source Version1.2.23 Updatenetsec
AsteriskOpen Source Version1.2.24
AsteriskOpen Source Version1.2.24 Updatenetsec
AsteriskOpen Source Version1.2.25
AsteriskOpen Source Version1.2.25 Updatenetsec
AsteriskOpen Source Version1.2.26
AsteriskOpen Source Version1.2.26 Updatenetsec
AsteriskOpen Source Version1.2.26.1
AsteriskOpen Source Version1.2.26.1 Updatenetsec
AsteriskOpen Source Version1.2.26.2
AsteriskOpen Source Version1.2.26.2 Updatenetsec
AsteriskOpen Source Version1.2.27
AsteriskOpen Source Version1.2.28
AsteriskOpen Source Version1.2.29
AsteriskOpen Source Version1.2.30
AsteriskOpen Source Version1.2.30.2
AsteriskOpen Source Version1.2.30.3
AsteriskOpen Source Version1.2.30.4
AsteriskOpen Source Version1.2.31
AsteriskOpen Source Version1.2.32
AsteriskOpen Source Version1.2.33
AsteriskOpen Source Version1.2.34
AsteriskOpen Source Version1.4.0
AsteriskOpen Source Version1.4.0 Updatebeta2
AsteriskOpen Source Version1.4.0 Updatebeta3
AsteriskOpen Source Version1.4.0 Updatebeta4
AsteriskOpen Source Version1.4.1
AsteriskOpen Source Version1.4.2
AsteriskOpen Source Version1.4.3
AsteriskOpen Source Version1.4.4
AsteriskOpen Source Version1.4.5
AsteriskOpen Source Version1.4.6
AsteriskOpen Source Version1.4.7
AsteriskOpen Source Version1.4.7.1
AsteriskOpen Source Version1.4.8
AsteriskOpen Source Version1.4.9
AsteriskOpen Source Version1.4.10
AsteriskOpen Source Version1.4.10.1
AsteriskOpen Source Version1.4.11
AsteriskOpen Source Version1.4.12
AsteriskOpen Source Version1.4.12.1
AsteriskOpen Source Version1.4.13
AsteriskOpen Source Version1.4.14
AsteriskOpen Source Version1.4.15
AsteriskOpen Source Version1.4.16
AsteriskOpen Source Version1.4.16.1
AsteriskOpen Source Version1.4.16.2
AsteriskOpen Source Version1.4.17
AsteriskOpen Source Version1.4.18
AsteriskOpen Source Version1.4.18.1
AsteriskOpen Source Version1.4.19
AsteriskOpen Source Version1.4.19 Updaterc-2
AsteriskOpen Source Version1.4.19 Updaterc1
AsteriskOpen Source Version1.4.19 Updaterc2
AsteriskOpen Source Version1.4.19 Updaterc3
AsteriskOpen Source Version1.4.19 Updaterc4
AsteriskOpen Source Version1.4.19.1
AsteriskOpen Source Version1.4.19.2
AsteriskOpen Source Version1.4.20
AsteriskOpen Source Version1.4.20 Updaterc1
AsteriskOpen Source Version1.4.20 Updaterc2
AsteriskOpen Source Version1.4.20 Updaterc3
AsteriskOpen Source Version1.4.21
AsteriskOpen Source Version1.4.21 Updaterc1
AsteriskOpen Source Version1.4.21 Updaterc2
AsteriskOpen Source Version1.4.21.1
AsteriskOpen Source Version1.4.21.2
AsteriskOpen Source Version1.4.22
AsteriskOpen Source Version1.4.22 Updaterc3
AsteriskOpen Source Version1.4.22 Updaterc4
AsteriskOpen Source Version1.4.22.1
AsteriskOpen Source Version1.4.22.2
AsteriskOpen Source Version1.4.23
AsteriskOpen Source Version1.4.23 Updaterc1
AsteriskOpen Source Version1.4.23 Updaterc2
AsteriskOpen Source Version1.4.23 Updaterc3
AsteriskOpen Source Version1.4beta
AsteriskOpen Source Version1.6.0 Updatebeta1
AsteriskOpen Source Version1.6.0 Updatebeta2
AsteriskOpen Source Version1.6.0 Updatebeta3
AsteriskOpen Source Version1.6.0 Updatebeta4
AsteriskOpen Source Version1.6.0 Updatebeta5
AsteriskOpen Source Version1.6.0 Updatebeta7
AsteriskOpen Source Version1.6.0 Updatebeta7.1
AsteriskOpen Source Version1.6.0 Updatebeta8
AsteriskOpen Source Version1.6.0 Updatebeta9
AsteriskOpen Source Version1.6.0 Updaterc4
AsteriskOpen Source Version1.6.0 Updaterc5
AsteriskOpen Source Version1.6.0 Updaterc6
AsteriskOpen Source Version1.6.0.1
AsteriskOpen Source Version1.6.0.2
AsteriskOpen Source Version1.6.0.3
AsteriskOpen Source Version1.6.0.3 Updaterc1
AsteriskOpen Source Version1.6.1.0 Updaterc1
AsteriskOpen Source Version1.6.1.0 Updaterc2
AsteriskOpen Source Version1.6.1.5
AsteriskOpensource Version1.4.23.2
AsteriskOpensource Version1.4.24
AsteriskOpensource Version1.4.24.1
AsteriskOpensource Version1.4.26
AsteriskOpensource Version1.4.26.1
SangomaAsterisk Version1.6.1
SangomaAsterisk Version1.6.1.4
AsteriskAppliance S800i Version1.3
AsteriskAppliance S800i Version1.3.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.84% 0.726
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.