Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
asterisk 拒绝服务漏洞
Vulnerability Description
修订版 72630以前的Asterisk 1.2和修订版65679以前的1.4中的IAX2 channel driver (chan_iax2),一旦置好 允许接受未授权访问并向一条新信息中的一个未经核对的源IP地址发送"early audio"时,远程攻击者togguo一个欺骗性的NEW信息来造成拒绝服务(流量增大)。
CVSS Information
N/A
Vulnerability Type
N/A