CVE-2023-49294: Asterisk Path Traversal vulnerability
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the livedangerously is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49294?
CVE-2023-49294 has been classified as a high severity vulnerability.
How do I fix CVE-2023-49294?
To fix CVE-2023-49294, upgrade to Asterisk version 18.20.1, 20.5.1, 21.0.1, or certified-asterisk version 18.9-cert6 or above.
What does CVE-2023-49294 allow an attacker to do?
CVE-2023-49294 allows an attacker to read any arbitrary file, bypassing the need for the 'live_dangerously' setting.
Which versions of Asterisk are affected by CVE-2023-49294?
Versions prior to Asterisk 18.20.1, 20.5.1, 21.0.1, and certified-asterisk versions before 18.9-cert6 are affected by CVE-2023-49294.
Can I check for CVE-2023-49294 on my system?
Yes, you should compare your current Asterisk version against the versions listed as affected by CVE-2023-49294.