5.8
CVSSv2

CVE-2008-1333

Published: 20/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Format string vulnerability in Asterisk Open Source 1.6.x prior to 1.6.0-beta6 might allow remote malicious users to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.

Vulnerable Product Search on Vulmon Subscribe to Product

asterisk open source 1.6.0 beta4

asterisk open source 1.6.0 beta3

asterisk open source 1.6.0 beta5

asterisk open source 1.6.0 beta2

asterisk open source 1.6.0 beta1

Vendor Advisories

Several remote vulnerabilities have been discovered in Asterisk, a free software PBX and telephony toolkit The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-6430 Tilghman Lesher discovered that database-based registrations are insufficiently validated This only affects setups, which are conf ...