Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.
2008-03-20T00:44:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.8 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | asterisk | open_source | 1.6.0_beta1 | Yes |
Application | asterisk | open_source | 1.6.0_beta2 | Yes |
Application | asterisk | open_source | 1.6.0_beta3 | Yes |
Application | asterisk | open_source | 1.6.0_beta4 | Yes |
Application | asterisk | open_source | 1.6.0_beta5 | Yes |