The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asterisk | Asterisk | 1.2.13 (including) | 1.2.13 (including) |
Asterisk | Ubuntu | dapper | * |
Asterisk | Ubuntu | devel | * |
Asterisk | Ubuntu | edgy | * |
Asterisk | Ubuntu | feisty | * |
Asterisk | Ubuntu | gutsy | * |
Asterisk | Ubuntu | hardy | * |
Asterisk | Ubuntu | intrepid | * |
Asterisk | Ubuntu | jaunty | * |
Asterisk | Ubuntu | karmic | * |