Asterisk Project Security Advisory - AST-2017-006

Discussion in 'News Aggregator' started by Packet Storm, 1 Sep 2017.

  1. Packet Storm

    Packet Storm Guest

    Asterisk Project Security Advisory - The app_minivm module has an externnotify program configuration option that is executed by the MinivmNotify dialplan application. The application uses the caller-id name and number as part of a built string passed to the OS shell for interpretation and execution. Since the caller-id name and number can come from an untrusted source, a crafted caller-id name or number allows an arbitrary shell command injection.

    Continue reading...
     

Share This Page

Loading...