SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade asterisk | Jul 30, 2024 | Nov 30, 2007 |
| Gentoo Linux | — | Upgrade net-misc/asterisk. | Oct 30, 2017 | Nov 29, 2007 |
| Suse | — | Upgrade asteriskUpgrade asterisk-spandspUpgrade asterisk-odbcUpgrade asterisk-alsaUpgrade asterisk-zaptelUpgrade suse-releaseUpgrade asterisk-pgsql | Feb 17, 2015 | Nov 29, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub