Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) header.
2013-04-01T16:55:03.893
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | asterisk | open_source | 11.0.0 | Yes |
Application | asterisk | open_source | 11.0.0 | Yes |
Application | asterisk | open_source | 11.0.0 | Yes |
Application | asterisk | open_source | 11.0.0 | Yes |
Application | asterisk | open_source | 11.0.0 | Yes |
Application | asterisk | open_source | 11.0.1 | Yes |
Application | asterisk | open_source | 11.0.2 | Yes |
Application | asterisk | open_source | 11.1.0 | Yes |
Application | asterisk | open_source | 11.1.0 | Yes |
Application | asterisk | open_source | 11.1.0 | Yes |
Application | asterisk | open_source | 11.1.1 | Yes |
Application | asterisk | open_source | 11.1.2 | Yes |
Application | asterisk | open_source | 11.2.0 | Yes |
Application | asterisk | open_source | 11.2.0 | Yes |
Application | asterisk | open_source | 11.2.0 | Yes |
Application | asterisk | open_source | 11.2.1 | Yes |