Asterisk PBX Multiple Logging Format...

- AV AC AU C I A
发布: 2004-06-18
修订: 2025-04-13

It is reported that Asterisk is susceptible to format string vulnerabilities in its logging functions. An attacker may use these vulnerabilities to corrupt memory, and read or write arbitrary memory. Remote code execution is likely possible. Due to the nature of these vulnerabilities, there may exist many different avenues of attack. Anything that can potentially call the logging functions with user-supplied data is vulnerable. Versions 0.7.0 through to 0.7.2 are reported vulnerable.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息