CVE Database
/

CVE-2010-0685

Back to search

CVE-2010-0685

Published: Feb 23, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable and wildcard pattern matches, allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the variable is expanded, as demonstrated using the Dial application to process a crafted SIP INVITE message that adds an unintended outgoing channel leg. NOTE: it could be argued that this is not a vulnerability in Asterisk, but a class of vulnerabilities that can occur in any program that uses this feature without the associated filtering functionality that is already available.

VendorProductVersions

n/a

n/a

affected
n/a

References

39096
third-party-advisory
x_refsource_SECUNIA
1023637
vdb-entry
x_refsource_SECTRACK
FEDORA-2010-3724
vendor-advisory
x_refsource_FEDORA
38641
third-party-advisory
x_refsource_SECUNIA
ADV-2010-0439
vdb-entry
x_refsource_VUPEN
asterisk-dial-weak-security(56397)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now