CVE-2008-1390: Critical severity asterisk vulnerability
The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1390?
CVE-2008-1390 has a medium severity rating due to its impact on authentication security.
How do I fix CVE-2008-1390?
To fix CVE-2008-1390, upgrade Asterisk to version 1.4.19-rc3 or later for 1.4.x and 1.6.0-beta6 or later for 1.6.x.
What versions are affected by CVE-2008-1390?
CVE-2008-1390 affects Asterisk versions from 1.4.1 to 1.4.18.1, and 1.6.x beta versions prior to 1.6.0-beta6.
What is the nature of the vulnerability in CVE-2008-1390?
CVE-2008-1390 involves the generation of insufficiently random manager ID values in the AsteriskGUI HTTP server.
Is CVE-2008-1390 a remote exploit?
Yes, CVE-2008-1390 can potentially be exploited remotely due to its nature as a web-based vulnerability.