Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x before 1.6.2.5 does not properly enforce remote host access controls when CIDR notation "/0" is used in permit= and deny= configuration rules, which causes an improper arithmetic shift and might allow remote attackers to bypass ACL rules and access services from unauthorized hosts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Digium Asterisk CIDR绕过主机访问限制规则漏洞
Vulnerability Description
Asterisk是一款PBX系统的软件,运行在Linux系统上,支持使用SIP,IAX,H323协议进行IP通话。 Asterisk Open Source 中的main/acl.c 存在访问控制绕过漏洞。当permit= 和 deny= 规则配置中用到CIDR符号“/0”时,因为没有正确的强制远程主机的访问控制权限,造成不正确的运算移位,远程攻击者从未经授权的主机绕过ACL规则并访问服务。
CVSS Information
N/A
Vulnerability Type
N/A