Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-1390
StatusCandidate
DescriptionThe AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.
PhaseAssigned (18.03.2008)
SecurityVulns:Asterisk multiple security vulnerabilities
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1390
ReferencesBID : 28316
 BUGTRAQ : 20080318 AST-2008-005: HTTP Manager ID is predictable
 CONFIRM : http://downloads.digium.com/pub/security/AST-2008-...
 SECUNIA : 29449

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru