Asterisk Missing ACL Check Remote Security Bypass Vulnerability
BID:36821
Info
Asterisk Missing ACL Check Remote Security Bypass Vulnerability
| Bugtraq ID: | 36821 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2009 12:00AM |
| Updated: | Nov 16 2009 07:56PM |
| Credit: | Thomas Athineou |
| Vulnerable: |
Red Hat Fedora 11 Asterisk Asterisk 1.6.1 0-rc2 Asterisk Asterisk 1.6.1 0-rc1 Asterisk Asterisk 1.6.1 .6 Asterisk Asterisk 1.6.1 .5 Asterisk Asterisk 1.6.1 Asterisk Asterisk 1.6.1.7 |
| Not Vulnerable: |
Asterisk Asterisk 1.6.1.8 |
Discussion
Asterisk Missing ACL Check Remote Security Bypass Vulnerability
Asterisk is prone to a security-bypass vulnerability.
Attackers can exploit this issue to make network calls that are supposed to be prohibited. This may lead to other attacks.
Asterisk is prone to a security-bypass vulnerability.
Attackers can exploit this issue to make network calls that are supposed to be prohibited. This may lead to other attacks.
Exploit / POC
Asterisk Missing ACL Check Remote Security Bypass Vulnerability
Attackers can use readily available utilities to exploit this issue.
Attackers can use readily available utilities to exploit this issue.
Solution / Fix
Asterisk Missing ACL Check Remote Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Asterisk Missing ACL Check Remote Security Bypass Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)
- Asterisk Security AST-2009-007 (Asterisk)
- AST-2009-007: ACL not respected on SIP INVITE ("Asterisk Security Team"
)