CVE Database
/

CVE-2013-7100

Back to search

CVE-2013-7100

Published: Dec 19, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Buffer overflow in the unpacksms16 function in apps/app_sms.c in Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before 10.12.4, and 11.x before 11.6.1; Asterisk with Digiumphones 10.x-digiumphones before 10.12.4-digiumphones; and Certified Asterisk 1.8.x before 1.8.15-cert4 and 11.x before 11.2-cert3 allows remote attackers to cause a denial of service (daemon crash) via a 16-bit SMS message with an odd number of bytes, which triggers an infinite loop.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2013:300
vendor-advisory
x_refsource_MANDRIVA
56294
third-party-advisory
x_refsource_SECUNIA
1029499
vdb-entry
x_refsource_SECTRACK
101100
vdb-entry
x_refsource_OSVDB
DSA-2835
vendor-advisory
x_refsource_DEBIAN
64364
vdb-entry
x_refsource_BID
asterisk-sms-message-dos(89825)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now