6
CVSSv2

CVE-2012-4737

Published: 31/08/2012 Updated: 19/04/2013
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

channels/chan_iax2.c in Asterisk Open Source 1.8.x prior to 1.8.15.1 and 10.x prior to 10.7.1, Certified Asterisk 1.8.11 prior to 1.8.11-cert7, Asterisk Digiumphones 10.x.x-digiumphones prior to 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 does not enforce ACL rules during certain uses of peer credentials, which allows remote authenticated users to bypass intended outbound-call restrictions by leveraging the availability of these credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 1.8.10.1

digium asterisk 1.8.10.0

digium asterisk 1.8.9.0

digium asterisk 1.8.9.2

digium asterisk 1.8.8.0

digium asterisk 1.8.8.1

digium asterisk 1.8.12.0

digium asterisk 1.8.0

digium asterisk 1.8.3

digium asterisk 1.8.3.1

digium asterisk 1.8.6.0

digium asterisk 1.8.7.0

digium asterisk 1.8.14.0

digium asterisk 1.8.14.1

digium asterisk 1.8.11.0

digium asterisk 1.8.9.3

digium asterisk 1.8.8.2

digium asterisk 1.8.12

digium asterisk 1.8.9.1

digium asterisk 1.8.1.1

digium asterisk 1.8.4.1

digium asterisk 1.8.1

digium asterisk 1.8.5

digium asterisk 1.8.4.4

digium asterisk 1.8.2.4

digium asterisk 1.8.13.0

digium asterisk 1.8.4

digium asterisk 1.8.2.3

digium asterisk 1.8.2.2

digium asterisk 1.8.5.0

digium asterisk 1.8.7.1

digium asterisk 1.8.15.0

digium asterisk 1.8.11.1

digium asterisk 1.8.1.2

digium asterisk 1.8.3.3

digium asterisk 1.8.2.1

digium asterisk 1.8.2

digium asterisk 1.8.4.3

digium asterisk 1.8.4.2

digium asterisk 1.8.3.2

digium asterisk 1.8.13.1

digium asterisk 10.3.0

digium asterisk 10.1.2

digium asterisk 10.1.1

digium asterisk 10.0.0

digium asterisk 10.4.2

digium asterisk 10.6.0

digium asterisk 10.7.0

digium asterisk 10.3.1

digium asterisk 10.2.0

digium asterisk 10.1.3

digium asterisk 10.5.1

digium asterisk 10.5.0

digium asterisk 10.6.1

digium asterisk 10.2.1

digium asterisk 10.1.0

digium asterisk 10.4.0

digium asterisk 10.0.1

digium asterisk 10.4.1

digium certified asterisk 1.8.11

digium asterisk 10.5.2

digium asterisk c.3.3.2

digium asterisk c.3.0

digium asterisk c.3.7.5

digium asterisk c.3.6.4

digium asterisk c.3.6.3

digium asterisk c.3.1.0

digium asterisk c.3.1.1

digium asterisk c.3.6.2

digium asterisk c.3.2.3

digium asterisk c.3.2.2

Vendor Advisories

Debian Bug report logs - #680470 Two security issues: AST-2012-010 / AST-2012-011 Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: F ...