CVE Vulnerabilities

CVE-2006-4346

Published: Aug 24, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Asterisk 1.2.10 supports the use of client-controlled variables to determine filenames in the Record function, which allows remote attackers to (1) execute code via format string specifiers or (2) overwrite files via directory traversals involving unspecified vectors, as demonstrated by the CALLERIDNAME variable.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 1.2.10 (including) 1.2.10 (including)
Asterisk Ubuntu dapper *
Asterisk Ubuntu devel *
Asterisk Ubuntu edgy *
Asterisk Ubuntu feisty *
Asterisk Ubuntu gutsy *
Asterisk Ubuntu hardy *
Asterisk Ubuntu intrepid *
Asterisk Ubuntu jaunty *
Asterisk Ubuntu karmic *

References