Asterisk SIP T.38 SDP Parsing Remote Stack Buffer Overflow Vulnerabilities

Attackers can use readily available networking utilities to exploit these issues.

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

The following proof-of-concept packet data is available:


 

Privacy Statement
Copyright 2010, SecurityFocus