CVE-2010-1224
01.04.2010, 21:30
main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x before 1.6.2.5 does not properly enforce remote host access controls when CIDR notation "/0" is used in permit= and deny= configuration rules, which causes an improper arithmetic shift and might allow remote attackers to bypass ACL rules and access services from unauthorized hosts.Enginsight
Vendor | Product | Version |
---|---|---|
digium | asterisk | 1.6.0 |
digium | asterisk | 1.6.0.1 |
digium | asterisk | 1.6.0.2 |
digium | asterisk | 1.6.0.3 |
digium | asterisk | 1.6.0.5 |
digium | asterisk | 1.6.0.6 |
digium | asterisk | 1.6.0.7 |
digium | asterisk | 1.6.0.8 |
digium | asterisk | 1.6.0.9 |
digium | asterisk | 1.6.0.10 |
digium | asterisk | 1.6.0.12 |
digium | asterisk | 1.6.0.13 |
digium | asterisk | 1.6.0.14 |
digium | asterisk | 1.6.0.15 |
digium | asterisk | 1.6.0.16:rc1 |
digium | asterisk | 1.6.0.16:rc2 |
digium | asterisk | 1.6.0.17 |
digium | asterisk | 1.6.0.18 |
digium | asterisk | 1.6.0.18:rc1 |
digium | asterisk | 1.6.0.18:rc2 |
digium | asterisk | 1.6.0.18:rc3 |
digium | asterisk | 1.6.0.19 |
digium | asterisk | 1.6.0.20:rc1 |
digium | asterisk | 1.6.0.21 |
digium | asterisk | 1.6.0.21:rc1 |
digium | asterisk | 1.6.0.22 |
digium | asterisk | 1.6.0.23:rc2 |
digium | asterisk | 1.6.0.24 |
digium | asterisk | 1.6.1 |
digium | asterisk | 1.6.1.1 |
digium | asterisk | 1.6.1.2 |
digium | asterisk | 1.6.1.4 |
digium | asterisk | 1.6.1.5 |
digium | asterisk | 1.6.1.6 |
digium | asterisk | 1.6.1.7:rc1 |
digium | asterisk | 1.6.1.7:rc2 |
digium | asterisk | 1.6.1.8 |
digium | asterisk | 1.6.1.9 |
digium | asterisk | 1.6.1.10 |
digium | asterisk | 1.6.1.10:rc1 |
digium | asterisk | 1.6.1.10:rc2 |
digium | asterisk | 1.6.1.10:rc3 |
digium | asterisk | 1.6.1.11 |
digium | asterisk | 1.6.1.12 |
digium | asterisk | 1.6.1.12:rc1 |
digium | asterisk | 1.6.1.13 |
digium | asterisk | 1.6.1.13:rc1 |
digium | asterisk | 1.6.1.14 |
digium | asterisk | 1.6.1.15:rc2 |
digium | asterisk | 1.6.1.16 |
digium | asterisk | 1.6.2.0 |
digium | asterisk | 1.6.2.0:rc2 |
digium | asterisk | 1.6.2.0:rc3 |
digium | asterisk | 1.6.2.0:rc4 |
digium | asterisk | 1.6.2.0:rc5 |
digium | asterisk | 1.6.2.0:rc6 |
digium | asterisk | 1.6.2.0:rc7 |
digium | asterisk | 1.6.2.0:rc8 |
digium | asterisk | 1.6.2.1 |
digium | asterisk | 1.6.2.1:rc1 |
digium | asterisk | 1.6.2.2 |
digium | asterisk | 1.6.2.3:rc2 |
digium | asterisk | 1.6.2.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References