Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 7: DLA-1122-1 Critical Asterisk Command Injection Advisory

debian lts
Calendar Grey October 5, 2017
Dist Debian Esm H88
Security patches for Asterisk address command injection weaknesses impacting Debian LTS. Enhanced protection through upgrade is advised.
A security vulnerability was discovered in Asterisk, an Open Source PBX and telephony toolkit, that may lead to unauthorized command execution

Summary

The app_minivm module has an "externnotify" program configuration option
that is executed by the MinivmNotify dialplan application. The
application uses the caller-id name and number as part of a built
string passed to the OS shell for interpretation and execution. Since
the caller-id name and number can come from an untrusted source, a
crafted caller-id name or number allows an arbitrary shell command
injection.

For Debian 7 "Wheezy", these problems have been fixed in version
1:1.8.13.1~dfsg1-3+deb7u7.

We recommend that you upgrade your asterisk packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: asterisk
Version: 1:1.8.13.1~dfsg1-3+deb7u7
CVE ID: CVE-2017-14100
Debian Bug: 873908

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here