Upstream information
Description
Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
NVD | |
---|---|
Base Score | 6.4 |
Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | Partial |
SUSE Security Advisories:
- SUSE-SR:2006:009, published Fri, 28 Apr 2006 16:00:00 +0000
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 02:22:00 2013CVE page last modified: Mon Sep 9 16:32:58 2024