Back to Database
Status published
High
CVE-2007-1594
The handle_response function in chan_sip.c in Asterisk before 1.2.17 and...
Vulnerability Description
The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Response code 0 in a SIP packet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-1594
Credits & Attribution
No credits recorded in the NVD database.
References
- http://svn.digium.com/view/asterisk/trunk/channels/chan_sip.c?r1=58907&r2=59038
- http://www.securityfocus.com/bid/23093
- http://www.vupen.com/english/advisories/2007/1077
- http://bugs.digium.com/view.php?id=9313
- http://www.securitytracker.com/id?1017809
- http://www.asterisk.org/node/48338
- http://www.novell.com/linux/security/advisories/2007_34_asterisk.html
- http://www.securityfocus.com/archive/1/463434/100/0/threaded
- http://secunia.com/advisories/24579
- http://security.gentoo.org/glsa/glsa-200704-01.xml
- http://secunia.com/advisories/25582
- http://secunia.com/advisories/24719
- http://www.sineapps.com/news.php?rssid=1707
- http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html
More from asterisk
View All →CVE-2025-57767
Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
High
7.5
CVE-2025-54995
Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Medium
6.5
CVE-2025-49832
Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation
Medium
6.5
CVE-2025-47780
cli_permissions.conf: deny option does not work for disallowing shell commands
Medium
4.8
CVE-2025-47779
Using malformed From header can forge identity with ";" or NULL in name portion
High
7.7
Affected Vendor
asterisk
View all reports →Affected Software
asterisk
Vulnerable Versions:
0.1.7, 0.1.8, 0.1.9, 0.1.9_1, 0.1.11, 0.2, 0.3, 0.4, 0.7.0, 0.7.1, 0.7.2, 0.9.0, 1.0, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.2.0_beta1, 1.2.0_beta2, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.12, 1.2.13, 1.2.14, 1.2.15, 1.2.16, 1.2.17, 1.4.1, 1.4_beta
Timeline
Official Publish:
March 22nd, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.