Asterisk Manager Interface Command Processing Remote Buffer Overflow Vulnerability
BID:14031
Info
Asterisk Manager Interface Command Processing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14031 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2081 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery of this issue is credited to Wade Alcorn. |
| Vulnerable: |
Asterisk Asterisk 1.0.7 Asterisk Asterisk CVS HEAD |
| Not Vulnerable: | |
Discussion
Asterisk Manager Interface Command Processing Remote Buffer Overflow Vulnerability
Asterisk manager interface is prone to a remote buffer overflow vulnerability. The issue manifests due to a lack of sufficient boundary checks performed by command line interface processing routines. Reports indicate that the issue may only be exploited if the manager interface is accessible and an attacker is able to write commands to the interface.
Under certain circumstances a remote attacker may exploit this issue to execute arbitrary code in the context of the affected software.
Asterisk manager interface is prone to a remote buffer overflow vulnerability. The issue manifests due to a lack of sufficient boundary checks performed by command line interface processing routines. Reports indicate that the issue may only be exploited if the manager interface is accessible and an attacker is able to write commands to the interface.
Under certain circumstances a remote attacker may exploit this issue to execute arbitrary code in the context of the affected software.
Exploit / POC
Asterisk Manager Interface Command Processing Remote Buffer Overflow Vulnerability
An exploit was developed by the discoverer o this issue. This exploit s not believed to be publicly available.
An exploit was developed by the discoverer o this issue. This exploit s not believed to be publicly available.
Solution / Fix
Asterisk Manager Interface Command Processing Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an update (1.08) to address this issue. Customers are advised to contact the vendor for further information regarding obtaining and applying this update.
Solution:
The vendor has released an update (1.08) to address this issue. Customers are advised to contact the vendor for further information regarding obtaining and applying this update.
References
Asterisk Manager Interface Command Processing Remote Buffer Overflow Vulnerability
References:
References: