PT-2007-6681 · Digium · Asterisk Zaptel

Michal Bucko

·

Publicado

2007-10-29

·

Atualizado

2024-08-07

·

CVE-2007-5690

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Asterisk Zaptel version 1.4.5.1
Description The issue is related to a buffer overflow in the sethdlc.c file, potentially allowing local users to gain privileges via a long device name in the ifr name field. However, the vendor disputes this, stating that the application requires root access and thus does not cross privilege boundaries.
Recommendations For Asterisk Zaptel version 1.4.5.1, consider restricting access to the sethdlc.c file or limiting the length of device names to prevent potential exploitation. As a temporary workaround, ensure that the application is run with the least privileges necessary to minimize the risk of privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5690

Produtos afetados

Asterisk Zaptel