7.5

CVE-2023-49294

Asterisk Path Traversal vulnerability

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digium ≫ Asterisk Version < 18.20.1
Digium ≫ Asterisk Version >= 19.0.0 < 20.5.1
Digium ≫ Asterisk Version 21.0.0
Sangoma ≫ Certified Asterisk Version 13.13.0
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc2
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc3
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert1-rc4
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert2
Sangoma ≫ Certified Asterisk Version 13.13.0 Update cert3
Sangoma ≫ Certified Asterisk Version 13.13.0 Update rc1
Sangoma ≫ Certified Asterisk Version 13.13.0 Update rc2
Sangoma ≫ Certified Asterisk Version 16.8.0 Update -
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert1
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert10
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert11
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert12
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert2
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert3
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert4
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert5
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert6
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert7
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert8
Sangoma ≫ Certified Asterisk Version 16.8.0 Update cert9
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert3
Sangoma ≫ Certified Asterisk Version 18.9 Update cert4
Sangoma ≫ Certified Asterisk Version 18.9 Update cert5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 45.57% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://lists.debian.org/debian-lts-announce/2023/12/msg00019.html
https://github.com/asterisk/asterisk/blob/master/main/manager.c#L3757
Product
https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5
Patch
https://github.com/asterisk/asterisk/security/advisories/GHSA-8857-hfmw-vg8f
Vendor Advisory