First published: Fri Sep 12 2003(Updated: )
SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asterisk | =0.4 | |
Asterisk | =0.1.9 | |
Asterisk | =0.2 | |
Asterisk | =0.1.9.1 | |
Asterisk | =0.1.8 | |
Asterisk | =0.1.7 | |
Asterisk | =0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-0779 is classified as high due to its potential for remote SQL execution.
To fix CVE-2003-0779, users should upgrade to a patched version of Asterisk that addresses the SQL injection vulnerability.
CVE-2003-0779 affects Asterisk versions 0.4, 0.3, 0.2, 0.1.9, 0.1.9.1, 0.1.8, and 0.1.7.
CVE-2003-0779 can enable remote attackers to execute arbitrary SQL commands in the database.
A temporary workaround for CVE-2003-0779 may involve restricting access to the CDR logging functionality until a patch is applied.