CVE-2003-0779: SQL Injection
Published Sep 12, 2003
·Updated
SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.
Affected Software
7 affected components
Asterisk=0.4
Asterisk=0.1.9
Asterisk=0.2
Asterisk=0.1.9.1
Asterisk=0.1.8
Asterisk=0.1.7
Asterisk=0.3
Event History
Sep 12, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Sep 22, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0779?
The severity of CVE-2003-0779 is classified as high due to its potential for remote SQL execution.
2
How do I fix CVE-2003-0779?
To fix CVE-2003-0779, users should upgrade to a patched version of Asterisk that addresses the SQL injection vulnerability.
3
What versions of Asterisk are affected by CVE-2003-0779?
CVE-2003-0779 affects Asterisk versions 0.4, 0.3, 0.2, 0.1.9, 0.1.9.1, 0.1.8, and 0.1.7.
4
What kind of attack can CVE-2003-0779 enable?
CVE-2003-0779 can enable remote attackers to execute arbitrary SQL commands in the database.
5
Is there a workaround for CVE-2003-0779?
A temporary workaround for CVE-2003-0779 may involve restricting access to the CDR logging functionality until a patch is applied.