Title : Debian Security Update Fixes Asterisk Call SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-4062 CVE ID : CVE-2007-6170
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-03
Technical Description
A vulnerability has been identified in Debian, which could be exploited by authenticated attackers to execute arbitrary SQL queries. This issue is caused by an error in Asterisk. For additional information, see : VUPEN/ADV-2007-4056
Debian GNU/Linux sarge - Upgrade to asterisk version 1:1.0.7.dfsg.1-2sarge6
Debian GNU/Linux etch - Upgrade to asterisk version 1:1.2.13~dfsg-2etch2 References