LWN.net Logo

asterisk: ignores ACL rules

Package(s):asterisk CVE #(s):CVE-2012-4737
Created:September 18, 2012 Updated:September 19, 2012
Description: From the Asterisk advisory:

When an IAX2 call is made using the credentials of a peer defined in a dynamic Asterisk Realtime Architecture (ARA) backend, the ACL rules for that peer are not applied to the call attempt. This allows for a remote attacker who is aware of a peer's credentials to bypass the ACL rules set for that peer.

Alerts:
Debian DSA-2550-1 2012-09-18
Debian DSA-2550-2 2012-09-26
Gentoo 201209-15 2012-09-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds