Release date: 2012-04-23
Updated on: 2012-04-24
Affected Systems:
Asterisk 10.x
Asterisk 1.x
Unaffected system:
Asterisk 10.3.1
Asterisk 1.8.11.1
Asterisk 1.6.2.24
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53206
CVE (CAN) ID: CVE-2012-2414
Asterisk is a free and open-source software that enables the Telephone User Switch (PBX) function.
Asterisk has a Security Restriction Bypass Vulnerability. Attackers can exploit this vulnerability to bypass certain security restrictions and execute shell commands in the context of affected applications.
<* Source: David Woolley
Link: https://issues.asterisk.org/jira/browse/ASTERISK-17465
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://downloads.asterisk.org/pub/security/