Asterisk malformed MIME boundary multiple buffer overflows and DoS
updated since 27.08.2007
SecurityVulns ID:8094
Threat Level:
Description:Multiple buffer overflows and crash on malformed MIME boundary if IMAP storage is used for Voicemail.
Affected:DIGIUM : Asterisk 1.4
CVE:CVE-2007-4521 (Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient listens to voicemail.)
Original documentdocumentASTERISK, AST-2007-022: Buffer overflows in voicemail when using IMAP storage (12.10.2007)
 documentASTERISK, AST-2007-021: Crash from invalid/corrupted MIME bodies when using voicemail with IMAP storage (27.08.2007)

