Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Asterisk Logger and Manager Format String Vulnerabilities

Asterisk is prone to multiple format-string vulnerabilities because the application fails to adequately sanitize user-supplied input before passing it as the format-specifier to a formatted-printing function.

A remote attacker may potentially execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.

These issues affect versions prior to Asterisk Open Source 1.6.0-beta6.







 

Privacy Statement
Copyright 2009, SecurityFocus