PT-2008-2972 · Digium+1 · Asterisk Appliance Developer Kit+4

Publicado

2008-03-24

·

Atualizado

2018-10-11

·

CVE-2008-1390

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asterisk Open Source versions 1.4.x through 1.4.19-rc2 Asterisk Open Source versions 1.6.x through 1.6.0-beta5 Asterisk Business Edition C.x.x through C.1.5 AsteriskNOW versions 1.0 through 1.0.1 Asterisk Appliance Developer Kit versions prior to revision 104704 s800i versions 1.0.x through 1.1.0.1
Description The AsteriskGUI HTTP server generates insufficiently random manager ID values, making it easier for remote attackers to hijack a manager session via a series of ID guesses.
Recommendations For Asterisk Open Source versions 1.4.x through 1.4.19-rc2, update to version 1.4.19-rc3 or later. For Asterisk Open Source versions 1.6.x through 1.6.0-beta5, update to version 1.6.0-beta6 or later. For Asterisk Business Edition C.x.x through C.1.5, update to version C.1.6 or later. For AsteriskNOW versions 1.0 through 1.0.1, update to version 1.0.2 or later. For Asterisk Appliance Developer Kit versions prior to revision 104704, update to revision 104704 or later. For s800i versions 1.0.x through 1.1.0.1, update to version 1.1.0.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1390

Produtos afetados

Asterisk Appliance Developer Kit
Asterisk Business Edition
Asterisk Open Source
Asterisknow
S800I