The Skinny channel driver (chan_skinny) in Asterisk Open Source before 1.4.10, AsteriskNOW before beta7, Appliance Developer Kit before 0.7.0, and Appliance s800i before 1.0.3 allows remote authenticated users to cause a denial of service (application crash) via a CAPABILITIES_RES_MESSAGE packet with a capabilities count larger than the capabilities_res_message array population.
2007-08-09T21:17:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:N/A:P
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | asterisk | asterisk | ≤ 1.4.9 | Yes |
Application | asterisk | asterisk_appliance_developer_kit | ≤ 0.6.0 | Yes |
Application | asterisk | asterisknow | ≤ beta_6 | Yes |
Application | asterisk | s800i | ≤ 1.0.2 | Yes |