Unrated severityNVD Advisory· Published Jul 18, 2007· Updated Apr 23, 2026
CVE-2007-3763
CVE-2007-3763
Description
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.
Affected products
36cpe:2.3:a:asterisk:asterisk:1.0:*:*:*:*:*:*:*+ 30 more
- cpe:2.3:a:asterisk:asterisk:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.0_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.0_beta2:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.15:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.16:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.17:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.4.4_2007-04-27:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:1.4_beta:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:a:*:business:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:b.1.3.2:*:business:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:b.1.3.3:*:business:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk:b.2.2.0:*:business:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:*:*:*:*:*:*:*:*Range: <=0.4
cpe:2.3:a:asterisk:asterisknow:beta_5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:asterisk:asterisknow:beta_5:*:*:*:*:*:*:*
- cpe:2.3:a:asterisk:asterisknow:beta_6:*:*:*:*:*:*:*
cpe:2.3:h:asterisk:s800i_appliance:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:h:asterisk:s800i_appliance:1.0:*:*:*:*:*:*:*
- cpe:2.3:h:asterisk:s800i_appliance:1.0.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- ftp.digium.com/pub/asa/ASA-2007-015.pdfnvdPatchVendor Advisory
- bugs.gentoo.org/show_bug.cginvd
- secunia.com/advisories/26099nvd
- secunia.com/advisories/29051nvd
- security.gentoo.org/glsa/glsa-200802-11.xmlnvd
- www.debian.org/security/2007/dsa-1358nvd
- www.novell.com/linux/security/advisories/2007_15_sr.htmlnvd
- www.securityfocus.com/bid/24950nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/2563nvd
News mentions
0No linked articles in our index yet.