Unrated severityNVD Advisory· Published May 17, 2007· Updated Apr 23, 2026
CVE-2007-1693
CVE-2007-1693
Description
The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using an incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter.
Affected products
1- cpe:2.3:a:yate:yet_another_telephony_engine:*:*:*:*:*:*:*:*Range: <=1.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- securityreason.com/securityalert/2716nvdExploitThird Party Advisory
- voip.null.ro/cgi-bin/cvsweb.cgi/yate/modules/ysipchan.cppnvdIssue TrackingThird Party Advisory
- www.securityfocus.com/archive/1/467289/100/200/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/23746nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.