Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4737

Overview

Vulnerability Score 6.0 6.0
CVE Id CVE-2012-4737
Last Modified 18 Apr 2013 11:25:34
Published 31 Aug 2012 10:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2012-4737

Summary

channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 does not enforce ACL rules during certain uses of peer credentials, which allows remote authenticated users to bypass intended outbound-call restrictions by leveraging the availability of these credentials.

Vulnerable Systems

Application

  • Digium Asterisk 1.8.0

  • Digium Asterisk 1.8.1

  • Digium Asterisk 1.8.1.1

  • Digium Asterisk 1.8.1.2

  • Digium Asterisk 1.8.10.0

  • Digium Asterisk 1.8.10.1

  • Digium Asterisk 1.8.11.0

  • Digium Asterisk 1.8.11.1

  • Digium Asterisk 1.8.12

  • Digium Asterisk 1.8.12.0

  • Digium Asterisk 1.8.13.0

  • Digium Asterisk 1.8.13.1

  • Digium Asterisk 1.8.14.0

  • Digium Asterisk 1.8.14.1

  • Digium Asterisk 1.8.15.0

  • Digium Asterisk 1.8.2

  • Digium Asterisk 1.8.2.1

  • Digium Asterisk 1.8.2.2

  • Digium Asterisk 1.8.2.3

  • Digium Asterisk 1.8.2.4

  • Digium Asterisk 1.8.3

  • Digium Asterisk 1.8.3.1

  • Digium Asterisk 1.8.3.2

  • Digium Asterisk 1.8.3.3

  • Digium Asterisk 1.8.4

  • Digium Asterisk 1.8.4.1

  • Digium Asterisk 1.8.4.2

  • Digium Asterisk 1.8.4.3

  • Digium Asterisk 1.8.4.4

  • Digium Asterisk 1.8.5

  • Digium Asterisk 1.8.5.0

  • Digium Asterisk 1.8.6.0

  • Digium Asterisk 1.8.7.0

  • Digium Asterisk 1.8.7.1

  • Digium Asterisk 1.8.8.0

  • Digium Asterisk 1.8.8.1

  • Digium Asterisk 1.8.8.2

  • Digium Asterisk 1.8.9.0

  • Digium Asterisk 1.8.9.1

  • Digium Asterisk 1.8.9.2

  • Digium Asterisk 1.8.9.3

  • Digium Asterisk 10.0.0

  • Digium Asterisk 10.0.1

  • Digium Asterisk 10.1.0

  • Digium Asterisk 10.1.1

  • Digium Asterisk 10.1.2

  • Digium Asterisk 10.1.3

  • Digium Asterisk 10.2.0

  • Digium Asterisk 10.2.1

  • Digium Asterisk 10.3.0

  • Digium Asterisk 10.3.1

  • Digium Asterisk 10.4.0

  • Digium Asterisk 10.4.1

  • Digium Asterisk 10.4.2

  • Digium Asterisk 10.5.0

  • Digium Asterisk 10.5.1

  • Digium Asterisk 10.5.2

  • Digium Asterisk 10.6.0

  • Digium Asterisk 10.6.1

  • Digium Asterisk 10.7.0

  • Digium Asterisk C.3.0

  • Digium Asterisk C.3.1.0

  • Digium Asterisk C.3.1.1

  • Digium Asterisk C.3.2.2

  • Digium Asterisk C.3.2.3

  • Digium Asterisk C.3.3.2

  • Digium Asterisk C.3.6.2

  • Digium Asterisk C.3.6.3

  • Digium Asterisk C.3.6.4

  • Digium Asterisk C.3.7.5

  • Digium Certified Asterisk 1.8.11


References

CONFIRM - http://downloads.asterisk.org/pub/security/AST-2012-013.html

DEBIAN - DSA-2550

BID - 55335

SECTRACK - 1027461

SECUNIA - 50756

SECUNIA - 50687


Last Updated: 27 May 2016 11:00:26