Asterisk CVE-2017-14100 Command Injection Vulnerability
BID:100582
Info
Asterisk CVE-2017-14100 Command Injection Vulnerability
| Bugtraq ID: | 100582 |
| Class: | Unknown |
| CVE: |
CVE-2017-14100 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2017 12:00AM |
| Updated: | Jul 01 2017 12:00AM |
| Credit: | Corey Farrell. |
| Vulnerable: |
Asterisk Open Source 14.2.1 Asterisk Open Source 13.15 Asterisk Open Source 13.14.1 Asterisk Open Source 13.13.1 Asterisk Open Source 13.13 Asterisk Open Source 13.12 Asterisk Open Source 11.25.1 Asterisk Open Source 11.12.1 Asterisk Open Source 14.0 Asterisk Open Source 13.0 Asterisk Open Source 11.0 Asterisk Certified Asterisk 13.13-cert4 Asterisk Certified Asterisk 13.13-cert3 Asterisk Certified Asterisk 13.13 Asterisk Certified Asterisk 11.6 |
| Not Vulnerable: |
Asterisk Open Source 14.6.1 Asterisk Open Source 13.17.1 Asterisk Open Source 11.25.2 Asterisk Certified Asterisk 13.13-cert5 Asterisk Certified Asterisk 11.6-cert17 |
Discussion
Asterisk CVE-2017-14100 Command Injection Vulnerability
Asterisk is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application; this may aid in further attacks.
Asterisk is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application; this may aid in further attacks.
Exploit / POC
Asterisk CVE-2017-14100 Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Asterisk CVE-2017-14100 Command Injection Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- asterisk: CVE-2017-14100: AST-2017-006: Shell access command injection inapp_min (Bernhard Schmidt)
- Asterisk Project Security Advisory - AST-2017-006 (Asterisk)
- core: ast_safe_system command injection possible. (Asterisk)