Asterisk Project Security Advisory - AST-2018-008

Discussion in 'News Aggregator' started by Packet Storm, 12 Jun 2018.

  1. Packet Storm

    Packet Storm Guest

    Asterisk Project Security Advisory - When endpoint specific ACL rules block a SIP request they respond with a 403 forbidden. However, if an endpoint is not identified then a 401 unauthorized response is sent. This vulnerability just discloses which requests hit a defined endpoint. The ACL rules cannot be bypassed to gain access to the disclosed endpoints.

    Continue reading...
     

Share This Page

Loading...