CVE-2019-18610
22.11.2019, 18:15
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.Enginsight
Vendor | Product | Version |
---|---|---|
digium | asterisk | 13.0.0 ≤ 𝑥 < 13.29.2 |
digium | asterisk | 16.0.0 ≤ 𝑥 < 16.6.2 |
digium | asterisk | 17.0.0 ≤ 𝑥 < 17.0.1 |
digium | certified_asterisk | 13.21.0 |
digium | certified_asterisk | 13.21.0:cert1 |
digium | certified_asterisk | 13.21.0:cert2 |
digium | certified_asterisk | 13.21.0:cert3 |
digium | certified_asterisk | 13.21.0:cert4 |
digium | certified_asterisk | 13.21.0:rc1 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References