what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Asterisk Project Security Advisory - AST-2013-007

Asterisk Project Security Advisory - AST-2013-007
Posted Dec 17, 2013
Authored by David Lee | Site asterisk.org

Asterisk Project Security Advisory - External control protocols, such as the Asterisk Manager Interface, often have the ability to get and set channel variables; this allows the execution of dial-plan functions. Dial-plan functions within Asterisk are incredibly powerful, which is wonderful for building applications using Asterisk. But during the read or write execution, certain dial-plan functions do much more. For example, reading the SHELL() function can execute arbitrary commands on the system Asterisk is running on. Writing to the FILE() function can change any file that Asterisk has write access to. When these functions are executed from an external protocol, that execution could result in a privilege escalation.

tags | advisory, arbitrary, shell, protocol
SHA-256 | d023c90a325ba8f94bb3cf31d665ef950f78277c35b78413f1a2879e54fbf60b

Asterisk Project Security Advisory - AST-2013-007

Change Mirror Download
               Asterisk Project Security Advisory - AST-2013-007

Product Asterisk
Summary Asterisk Manager User Dialplan Permission Escalation
Nature of Advisory Permission Escalation
Susceptibility Remote Authenticated Sessions
Severity Minor
Exploits Known None
Reported On November 25, 2013
Reported By Matt Jordan
Posted On December 16, 2013
Last Updated On December 16, 2013
Advisory Contact David Lee < dlee AT digium DOT com >
CVE Name Pending

Description External control protocols, such as the Asterisk Manager
Interface, often have the ability to get and set channel
variables; this allows the execution of dialplan functions.

Dialplan functions within Asterisk are incredibly powerful,
which is wonderful

for building applications using Asterisk. But during the
read or write execution, certain diaplan functions do much
more. For example, reading the SHELL() function can execute
arbitrary commands on the system Asterisk is running on.
Writing to the FILE() function can change any file that
Asterisk has write access to.

When these functions are executed from an external
protocol, that execution could result in a privilege
escalation.

Resolution Asterisk can now inhibit the execution of these functions
from external interfaces such as AMI, if live_dangerously in
the [options] section of asterisk.conf is set to no.

For backwards compatibility, live_dangerously defaults to
yes, and must be explicitly set to no to enable this
privilege escalation protection.

Affected Versions
Product Release Series
Asterisk Open Source 1.8.x All Versions
Asterisk Open Source 10.x All Versions
Asterisk with Digiumphones 10.x-digiumphones All Versions
Asterisk Open Source 11.x All Versions
Certified Asterisk 1.8.x All Versions
Certified Asterisk 11.x All Versions

Corrected In
Product Release
Asterisk Open Source 1.8.24.1, 10.12.4, 11.6.1
Asterisk with Digiumphones 10.12.4-digiumphones
Certified Asterisk 1.8.15-cert4, 11.2-cert3

Patches
SVN URL Revision
http://downloads.asterisk.org/pub/security/AST-2013-007-1.8.diff Asterisk 1.8
http://downloads.asterisk.org/pub/security/AST-2013-007-10.diff Asterisk 10
http://downloads.asterisk.org/pub/security/AST-2013-007-10-digiumphones.diff Asterisk
10-digiumphones
http://downloads.asterisk.org/pub/security/AST-2013-007-11.diff Asterisk 11
http://downloads.asterisk.org/pub/security/AST-2013-007-1.8.15.diff Certified
Asterisk 1.8.15
http://downloads.asterisk.org/pub/security/AST-2013-007-11.2.diff Certified
Asterisk 11.2

Links https://issues.asterisk.org/jira/browse/ASTERISK-22905

Asterisk Project Security Advisories are posted at
http://www.asterisk.org/security

This document may be superseded by later versions; if so, the latest
version will be posted at
http://downloads.digium.com/pub/security/AST-2013-007.pdf and
http://downloads.digium.com/pub/security/AST-2013-007.html

Revision History
Date Editor Revisions Made
12/16/2013 Matt Jordan Initial Revision

Asterisk Project Security Advisory - AST-2013-007
Copyright (c) 2013 Digium, Inc. All Rights Reserved.
Permission is hereby granted to distribute and publish this advisory in its
original, unaltered form.


Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close