CVE Database
/

CVE-2006-2923

Back to search

CVE-2006-2923

Published: Jun 9, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

The iax_net_read function in the iaxclient open source library, as used in multiple products including (a) LoudHush 1.3.6, (b) IDE FISK 1.35 and earlier, (c) Kiax 0.8.5 and earlier, (d) DIAX, (e) Ziaxphone, (f) IAX Phone, (g) X-lite, (h) MediaX, (i) Extreme Networks ePhone, and (j) iaxComm before 1.2.0, allows remote attackers to execute arbitrary code via crafted IAX 2 (IAX2) packets with truncated (1) full frames or (2) mini-frames, which are detected in a length check but still processed, leading to buffer overflows related to negative length values.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-2286
vdb-entry
x_refsource_VUPEN
ADV-2006-2285
vdb-entry
x_refsource_VUPEN
20567
third-party-advisory
x_refsource_SECUNIA
20900
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2180
vdb-entry
x_refsource_VUPEN
20623
third-party-advisory
x_refsource_SECUNIA
20466
third-party-advisory
x_refsource_SECUNIA
18307
vdb-entry
x_refsource_BID
ADV-2006-2284
vdb-entry
x_refsource_VUPEN
GLSA-200606-30
vendor-advisory
x_refsource_GENTOO
20560
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now