|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Mon Feb 22 2010 - 20:57:12 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
----------------------------------------------------------------------
Public Beta of CSI and WSUS Integration
http://secunia.com/blog/74
----------------------------------------------------------------------
TITLE:
Asterisk Dialplan Wildcard Pattern Weakness
SECUNIA ADVISORY ID:
SA38641
VERIFY ADVISORY:
http://secunia.com/advisories/38641/
DESCRIPTION:
A weakness has been reported in Asterisk, which can lead to
unintended configurations.
The problem is that certain wildcard patterns in combination with
e.g. the "${EXTEN}" channel variable in a dialplan can lead to a
configuration that allows passing additional arguments to certain
applications (e.g. "Dial()"). The problem occurs when a channel
technology is used that accepts characters other than numbers and
letters (e.g. SIP).
The weakness is reported in the following products and versions:
* Asterisk Open Source 1.2.x (all versions)
* Asterisk Open Source 1.4.x (all versions)
* Asterisk Open Source 1.6.x (all versions)
* Asterisk Business Edition B.x.x (all versions)
* Asterisk Business Edition C.x.x (all versions)
SOLUTION:
The vendor recommends to check existing configurations and apply
security best practices (please see the vendor's advisory for
details).
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Hans Petter Selasky.
ORIGINAL ADVISORY:
http://downloads.asterisk.org/pub/security/AST-2010-002.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]