|
|
| |
|
| |
asterisk: ignores ACL rules
| Package(s): | asterisk |
CVE #(s): | CVE-2012-4737
|
| Created: | September 18, 2012 |
Updated: | September 19, 2012 |
| Description: |
From the Asterisk advisory:
When an IAX2 call is made using the credentials of a peer defined in a dynamic Asterisk Realtime Architecture (ARA) backend, the ACL rules for that peer are not applied to the call attempt. This allows for a remote attacker who is aware of a peer's credentials to bypass the ACL rules set for that peer. |
| Alerts: |
|
( Log in to post comments)
|
|
|