4.3
CVSSv2

CVE-2010-1224

Published: 01/04/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

main/acl.c in Asterisk Open Source 1.6.0.x prior to 1.6.0.25, 1.6.1.x prior to 1.6.1.17, and 1.6.2.x prior to 1.6.2.5 does not properly enforce remote host access controls when CIDR notation "/0" is used in permit= and deny= configuration rules, which causes an improper arithmetic shift and might allow remote malicious users to bypass ACL rules and access services from unauthorized hosts.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.6.0.23

digium asterisk 1.6.0.22

digium asterisk 1.6.0.18

digium asterisk 1.6.0.12

digium asterisk 1.6.0.10

digium asterisk 1.6.0.9

digium asterisk 1.6.0.1

digium asterisk 1.6.0

digium asterisk 1.6.1.7

digium asterisk 1.6.1.11

digium asterisk 1.6.1.12

digium asterisk 1.6.2.0

digium asterisk 1.6.2.1

digium asterisk 1.6.2.2

digium asterisk 1.6.0.24

digium asterisk 1.6.0.14

digium asterisk 1.6.0.13

digium asterisk 1.6.0.3

digium asterisk 1.6.0.2

digium asterisk 1.6.1.5

digium asterisk 1.6.1.6

digium asterisk 1.6.1.10

digium asterisk 1.6.0.21

digium asterisk 1.6.0.17

digium asterisk 1.6.0.16

digium asterisk 1.6.0.8

digium asterisk 1.6.0.7

digium asterisk 1.6.1

digium asterisk 1.6.1.1

digium asterisk 1.6.1.8

digium asterisk 1.6.1.9

digium asterisk 1.6.1.13

digium asterisk 1.6.2.3

digium asterisk 1.6.2.4

digium asterisk 1.6.1.16

digium asterisk 1.6.0.20

digium asterisk 1.6.0.19

digium asterisk 1.6.0.15

digium asterisk 1.6.0.6

digium asterisk 1.6.0.5

digium asterisk 1.6.1.2

digium asterisk 1.6.1.4

digium asterisk 1.6.1.14

digium asterisk 1.6.1.15

Vendor Advisories

Debian Bug report logs - #576560 asterisk: CVE-2010-1224 incorrect parsing of ACL rules Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Mon, 5 Apr 2 ...