CVE-2007-5358
Last modified
CVE-2007-5358 is a vulnerability of currently unknown severity. Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files.. EPSS estimates a 3.86% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | <= 1.4.12 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5358?
How severe is CVE-2007-5358?
How do I fix CVE-2007-5358?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5352Unspecified vulnerability in Local Security Authority Subsys…
- CVE-2007-5353Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-5354Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-5355The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Int…
- CVE-2007-5356Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-5357Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-5360Buffer overflow in OpenPegasus Management server, when compi…
- CVE-2007-5361The Communication Server in Alcatel-Lucent OmniPCX Enterpris…
- CVE-2007-5362Multiple PHP remote file inclusion vulnerabilities in the Av…
- CVE-2007-5363PHP remote file inclusion vulnerability in admin.panoramic.p…
- CVE-2007-5364Directory traversal vulnerability in payments/ideal_process.…
- CVE-2007-5365Stack-based buffer overflow in the cons_options function in …
Are you affected by CVE-2007-5358?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
