5.8
CVSSv2

CVE-2008-1333

Published: 20/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Format string vulnerability in Asterisk Open Source 1.6.x prior to 1.6.0-beta6 might allow remote malicious users to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.

Vulnerable Product Search on Vulmon Subscribe to Product

asterisk open source 1.6.0_beta3

asterisk open source 1.6.0_beta4

asterisk open source 1.6.0_beta5

asterisk open source 1.6.0_beta1

asterisk open source 1.6.0_beta2

Vendor Advisories

Several remote vulnerabilities have been discovered in Asterisk, a free software PBX and telephony toolkit The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-6430 Tilghman Lesher discovered that database-based registrations are insufficiently validated This only affects setups, which are conf ...