Asterisk CallerID Call Detail Records SQL Injection Vulnerability
BID:8599
Info
Asterisk CallerID Call Detail Records SQL Injection Vulnerability
| Bugtraq ID: | 8599 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0779 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | The discovery of this vulnerability has been credited to @stake. |
| Vulnerable: |
Asterisk Asterisk 0.4 Asterisk Asterisk 0.3 Asterisk Asterisk 0.2 Asterisk Asterisk 0.1.9 -1 Asterisk Asterisk 0.1.9 Asterisk Asterisk 0.1.8 Asterisk Asterisk 0.1.7 |
| Not Vulnerable: | |
Discussion
Asterisk CallerID Call Detail Records SQL Injection Vulnerability
Asterisk is prone to SQL injection attacks via malformed Call Detail Records (CDR) data. The problem specifically occurs when handling CallerID data within CDR data. The vulnerability occurs due to insufficient sanitization and could allow for the execution of SQL commands on the system. This could potentially be exploited by an attacker to influence the logic of SQL queries or to exploit vulnerabilities in the underlying database. Other attacks may also be possible.
Asterisk is prone to SQL injection attacks via malformed Call Detail Records (CDR) data. The problem specifically occurs when handling CallerID data within CDR data. The vulnerability occurs due to insufficient sanitization and could allow for the execution of SQL commands on the system. This could potentially be exploited by an attacker to influence the logic of SQL queries or to exploit vulnerabilities in the underlying database. Other attacks may also be possible.
Exploit / POC
Asterisk CallerID Call Detail Records SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Asterisk CallerID Call Detail Records SQL Injection Vulnerability
Solution:
This issue is said to have been addressed in the CVS tree on September 9th. This information has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue is said to have been addressed in the CVS tree on September 9th. This information has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Asterisk CallerID Call Detail Records SQL Injection Vulnerability
References:
References: