Bug#457063: asterisk: CVE-2007-6430 remote unauthenticated sessions

Nico Golde nion at debian.org
Wed Dec 19 13:38:53 UTC 2007


Package: asterisk
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for asterisk.

CVE-2007-6430[0]:
| Due to the way database-based registrations ("realtime")
| are processed, IP addresses are not checked when the
| username is correct and there is no password. An
| attacker may impersonate any user using host-based
| authentication without a secret, simply by guessing the
| username of that user. This is limited in scope to
| administrators who have set up the registration database
| ("realtime") for authentication and are using only
| host-based authentication, not passwords. However, both
| the SIP and IAX protocols are affected.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://downloads.digium.com/pub/security/AST-2007-027.html

Kind regards
Nico

--
Nico Golde - http://www.ngolde.de - nion at jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-voip-maintainers/attachments/20071219/9acc0e3f/attachment.pgp 


More information about the Pkg-voip-maintainers mailing list