CVE-2003-0761 describes a buffer overflow vulnerability in the Session Initiation Protocol (SIP) implementation of Asterisk releases prior to August 15, 2003, specifically within the get_msg_text function of chan_sip.c. This flaw allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted MESSAGE or INFO requests. With a CVSS score of 7.5, this vulnerability is considered high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, organizations using affected Asterisk versions should apply available patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.13CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:1.2.13:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.