|
Asterisk Logger and Manager Format String Vulnerabilities
Asterisk is prone to multiple format-string vulnerabilities because the application fails to adequately sanitize user-supplied input before passing it as the format-specifier to a formatted-printing function. A remote attacker may potentially execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service. These issues affect versions prior to Asterisk Open Source 1.6.0-beta6. |
|
|
Privacy Statement |