CVE-2008-1333

Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:asterisk:open_source:1.6.0_beta1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0_beta5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-03-20 00:44

Updated : 2023-12-10 10:51


NVD link : CVE-2008-1333

Mitre link : CVE-2008-1333

CVE.ORG link : CVE-2008-1333


JSON object : View

Products Affected

asterisk

  • open_source
CWE
CWE-134

Use of Externally-Controlled Format String