Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Gentoo: GLSA-200804-13 Normal: Asterisk SQL Injection And Session Hijacking

gentoo
Calendar Grey April 15, 2008
Dist Gentoo Esm H88
Several security flaws in Asterisk permit SQL injection and session takeover. Critical warning for users.
Multiple vulnerabilities have been found in Asterisk allowing for SQL injection, session hijacking and unauthorized usage.

Summary

Gentoo Linux Security Advisory GLSA 200804-13 https://security.gentoo.org/ Severity: Normal Title: Asterisk: Multiple vulnerabilities Date: April 14, 2008 Bugs: #200792, #202733, #213883 ID: 200804-13

Synopsis ======= Multiple vulnerabilities have been found in Asterisk allowing for SQL injection, session hijacking and unauthorized usage.
Background ========= Asterisk is an open source telephony engine and tool kit.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/asterisk < 1.2.27 >= 1.2.27
========== Asterisk upstream developers reported multiple vulnerabilities:
* The Call Detail Record Postgres logging engine (cdr_pgsql) does not correctly es...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3604853_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here