CVE-2008-1333

Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:asterisk:open_source:1.6.0_beta3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta2:*:*:*:*:*:*:*

Information

Published : 2008-03-19 17:44

Updated : 2018-10-11 13:31


NVD link : CVE-2008-1333

Mitre link : CVE-2008-1333


JSON object : View

CWE
CWE-134

Use of Externally-Controlled Format String

Advertisement

dedicated server usa

Products Affected

asterisk

  • open_source