PT-2006-3005 · Digium · Asterisk@Home

Francois Harvey

·

Publicado

2006-04-25

·

Atualizado

2018-10-18

·

CVE-2006-2021

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asterisk@Home versions prior to 2.8
Description The issue allows remote attackers to read arbitrary MP3, WAV, and GSM files via a full pathname in the recording parameter in the Asterisk Recording Interface (ARI) web interface. This can also be used to determine the existence of files.
Recommendations For versions prior to 2.8, update to version 2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the recordings/misc/audio.php file to minimize the risk of exploitation. Avoid using the recording parameter with full pathnames in the affected API endpoint until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2021

Produtos afetados

Asterisk@Home