Vulnerability Description
manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system privilege, which allows remote authenticated users to execute arbitrary commands via an Originate action that has an Async header in conjunction with an Application header.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | 1.4.0 |
Related Weaknesses (CWE)
References
- http://downloads.digium.com/pub/security/AST-2011-006.htmlVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058922.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059702.html
- http://openwall.com/lists/oss-security/2011/04/22/6
- http://secunia.com/advisories/44197Vendor Advisory
- http://secunia.com/advisories/44529
- http://securitytracker.com/id?1025433
- http://www.debian.org/security/2011/dsa-2225
- http://www.securityfocus.com/bid/47537
- http://www.vupen.com/english/advisories/2011/1086Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1107
- http://www.vupen.com/english/advisories/2011/1188
- http://downloads.digium.com/pub/security/AST-2011-006.htmlVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058922.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059702.html
FAQ
What is CVE-2011-1599?
CVE-2011-1599 is a vulnerability with a CVSS score of 9.0 (HIGH). manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x befor...
How severe is CVE-2011-1599?
CVE-2011-1599 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1599?
Check the references section above for vendor advisories and patch information. Affected products include: Digium Asterisk.