Vulnerabilities > CVE-2008-1333 - Use of Externally-Controlled Format String vulnerability in Asterisk Open Source
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Format String Injection An attacker includes formatting characters in a string input field on the target application. Most applications assume that users will provide static text and may respond unpredictably to the presence of formatting character. For example, in certain functions of the C programming languages such as printf, the formatting character %s will print the contents of a memory location expecting this location to identify a string and the formatting character %n prints the number of DWORD written in the memory. An attacker can use this to read or write to memory locations or files, or simply to manipulate the value of the resulting text in unexpected ways. Reading or writing memory may result in program crashes and writing memory could result in the execution of arbitrary code if the attacker can write to the program stack.
- String Format Overflow in syslog() This attack targets the format string vulnerabilities in the syslog() function. An attacker would typically inject malicious input in the format string parameter of the syslog function. This is a common problem, and many public vulnerabilities and associated exploits have been posted.
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1525.NASL |
description | Several remote vulnerabilities have been discovered in Asterisk, a free software PBX and telephony toolkit. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2007-6430 Tilghman Lesher discovered that database-based registrations are insufficiently validated. This only affects setups, which are configured to run without a password and only host-based authentication. - CVE-2008-1332 Jason Parker discovered that insufficient validation of From: headers inside the SIP channel driver may lead to authentication bypass and the potential external initiation of calls. - CVE-2008-1333 This update also fixes a format string vulnerability, which can only be triggered through configuration files under control of the local administrator. In later releases of Asterisk this issue is remotely exploitable and tracked as CVE-2008-1333. The status of the old stable distribution (sarge) is currently being investigated. If affected, an update will be released through security.debian.org. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31631 |
published | 2008-03-21 |
reporter | This script is Copyright (C) 2008-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/31631 |
title | Debian DSA-1525-1 : asterisk - several vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 28311 CVE(CAN) ID: CVE-2008-1333 Asterisk是开放源码的软件PBX,支持各种VoIP协议和设备。 Asterisk的日志和管理器功能实现上存在漏洞,远程攻击者可能利用此漏洞导致拒绝服务。 使用ast_verbose日志API调用所显示的日志消息没有显示为字符串,而是格式串;管理器命令command结果输出没有作为字符串附加到生成的响应消息中,而是附加为格式串。这两种情况都允许攻击者在输入中提交特意的格式串值导致崩溃。 Asterisk Asterisk 1.6.x Asterisk -------- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://downloads.digium.com/pub/telephony/asterisk target=_blank>http://downloads.digium.com/pub/telephony/asterisk</a> |
id | SSV:3075 |
last seen | 2017-11-19 |
modified | 2008-03-21 |
published | 2008-03-21 |
reporter | Root |
title | Asterisk日志函数及管理器远程格式串处理漏洞 |
References
- http://downloads.digium.com/pub/security/AST-2008-004.html
- http://downloads.digium.com/pub/security/AST-2008-004.html
- http://secunia.com/advisories/29426
- http://secunia.com/advisories/29426
- http://secunia.com/advisories/29456
- http://secunia.com/advisories/29456
- http://securitytracker.com/id?1019630
- http://securitytracker.com/id?1019630
- http://www.asterisk.org/node/48466
- http://www.asterisk.org/node/48466
- http://www.debian.org/security/2008/dsa-1525
- http://www.debian.org/security/2008/dsa-1525
- http://www.securityfocus.com/archive/1/489823/100/0/threaded
- http://www.securityfocus.com/archive/1/489823/100/0/threaded
- http://www.securityfocus.com/bid/28311
- http://www.securityfocus.com/bid/28311
- http://www.vupen.com/english/advisories/2008/0928
- http://www.vupen.com/english/advisories/2008/0928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41301
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41301