Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1599
Description:manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system privilege, which allows remote authenticated users to execute arbitrary commands via an Originate action that has an Async header in conjunction with an Application header.
Test IDs: 1.3.6.1.4.1.25623.1.0.69694   1.3.6.1.4.1.25623.1.0.69568   1.3.6.1.4.1.25623.1.0.69530   1.3.6.1.4.1.25623.1.0.69680  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1599
1025433
http://securitytracker.com/id?1025433
44197
http://secunia.com/advisories/44197
44529
http://secunia.com/advisories/44529
47537
http://www.securityfocus.com/bid/47537
ADV-2011-1086
http://www.vupen.com/english/advisories/2011/1086
ADV-2011-1107
http://www.vupen.com/english/advisories/2011/1107
ADV-2011-1188
http://www.vupen.com/english/advisories/2011/1188
DSA-2225
http://www.debian.org/security/2011/dsa-2225
FEDORA-2011-5835
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058922.html
FEDORA-2011-6208
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059702.html
[oss-security] 20110422 Re: CVE Request -- Asterisk Security Vulnerability
http://openwall.com/lists/oss-security/2011/04/22/6
http://downloads.digium.com/pub/security/AST-2011-006.html
http://downloads.digium.com/pub/security/AST-2011-006.html




© 1998-2025 E-Soft Inc. All rights reserved.