← Vulnerability feed

Vulnerability record · CVE-2007-1561 · published 21 March 2007

CVE-2007-1561: Asterisk vulnerability

Asterisk · Asterisk

The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.

7.8 CVSS 2.0 High EPSS 14% · top 3.5%
7.8CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://asterisk.org/node/48339
http://marc.info/?l=full-disclosure&m=117432783011737&w=2
http://secunia.com/advisories/24564
http://secunia.com/advisories/24719
http://secunia.com/advisories/25582
http://security.gentoo.org/glsa/glsa-200704-01.xml
http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html
http://www.debian.org/security/2007/dsa-1358
http://www.novell.com/linux/security/advisories/2007_34_asterisk.html
http://www.osvdb.org/34479
http://www.securityfocus.com/archive/1/463434/100/0/threaded
http://www.securityfocus.com/bid/23031 Patch
http://www.securitytracker.com/id?1017794
http://www.sineapps.com/news.php?rssid=1707
http://www.vupen.com/english/advisories/2007/1039
https://exchange.xforce.ibmcloud.com/vulnerabilities/33068
http://asterisk.org/node/48339
http://marc.info/?l=full-disclosure&m=117432783011737&w=2
http://secunia.com/advisories/24564
http://secunia.com/advisories/24719
http://secunia.com/advisories/25582
http://security.gentoo.org/glsa/glsa-200704-01.xml
http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html
http://www.debian.org/security/2007/dsa-1358
http://www.novell.com/linux/security/advisories/2007_34_asterisk.html
http://www.osvdb.org/34479
http://www.securityfocus.com/archive/1/463434/100/0/threaded
http://www.securityfocus.com/bid/23031 Patch
http://www.securitytracker.com/id?1017794
http://www.sineapps.com/news.php?rssid=1707
http://www.vupen.com/english/advisories/2007/1039
https://exchange.xforce.ibmcloud.com/vulnerabilities/33068

Track CVE-2007-1561 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2488Asterisk vulnerabilityThe IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss …EPSS 4.3%9.3CVE-2008-1390Asterisk vulnerabilityThe AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, Asteri…EPSS 3.8%9.3CVE-2007-3762Asterisk vulnerabilityStack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1,…EPSS 5.5%8.8CVE-2024-42365Asterisk vulnerabilityAsterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-…EPSS 4.7%8.8CVE-2008-1332Asterisk permissions and access controls vulnerabilityUnspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2…EPSS 2.3%7.8CVE-2009-2346Asterisk memory buffer overflow vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.…EPSS 2.6%7.8CVE-2008-3263Asterisk vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before …EPSS 28%7.8CVE-2007-2294Asterisk vulnerabilityThe Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 auth…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2007-1561), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.