CVE-2007-1561

Publication date 21 March 2007

Last updated 17 July 2025


Ubuntu priority

Description

The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.

Status

Package Ubuntu Release Status
asterisk 7.10 gutsy
Fixed 1:1.4.2~dfsg-1
7.04 feisty
Fixed 1.2.16~dfsg-1ubuntu3.1
6.10 edgy
Fixed 1.2.12.1.dfsg-1ubuntu1.4
6.06 LTS dapper
Fixed 1.2.7.1.dfsg-2ubuntu3.4


Access our resources on patching vulnerabilities