rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before, 1.6.0.x before, and 1.6.1.x before; Business Edition B.x.x before B.2.5.13, C.2.x.x before C.2.4.6, and C.3.x.x before C.3.2.3; and s800i 1.3.x before allows remote attackers to cause a denial of service (daemon crash) via an RTP comfort noise payload with a long data length.

Related Vulnerabilities

platform vulnerability
CVE-2009-4055 asterisk