Unrated severityNVD Advisory· Published Apr 26, 2007· Updated Apr 23, 2026
CVE-2007-2293
CVE-2007-2293
Description
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/24977nvdPatchVendor Advisory
- www.securitytracker.com/idnvdPatch
- www.securityfocus.com/bid/23648nvdExploitPatch
- securityreason.com/securityalert/2645nvd
- www.asterisk.org/files/ASA-2007-010.pdfnvd
- www.osvdb.org/35368nvd
- www.securityfocus.com/archive/1/466883/100/0/threadednvd
- www.securityfocus.com/archive/1/472804/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/1534nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33895nvd
News mentions
0No linked articles in our index yet.