|
|
| |
| Asterisk is prone to a security-bypass vulnerability that affects the manager interface. |
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/53206
The information has been provided by David Woolley.
|
| |
Vulnerable Systems:
* Asterisk Asterisk Business Edition C.3.7.3 and prior
An attacker can exploit this issue to bypass certain security restrictions and execute shell commands within the context of the affected application.
Vendor Status:
Vendor as issued an update for this vulnerablity.
Patch Availability:
https://issues.asterisk.org/jira/browse/ASTERISK-17465
CVE Information:
CVE-2012-2414
Disclosure Timeline:
Published: Apr 23 2012
Updated: Jun 22 2012
|
|
blog comments powered by
|