CVE-2023-49294

NameCVE-2023-49294
DescriptionAsterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3696-1, DSA-5596-1, ELA-1032-1
Debian Bugs1059032

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
asterisk (PTS)jessie, jessie (lts)1:11.13.1~dfsg-2+deb8u8vulnerable
stretch (security)1:13.14.1~dfsg-2+deb9u6vulnerable
stretch (lts), stretch1:13.14.1~dfsg-2+deb9u10fixed
buster, buster (lts)1:16.28.0~dfsg-0+deb10u5fixed
buster (security)1:16.28.0~dfsg-0+deb10u4fixed
bullseye1:16.28.0~dfsg-0+deb11u4fixed
bullseye (security)1:16.28.0~dfsg-0+deb11u5fixed
sid1:22.0.0~dfsg+~cs6.14.60671435-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
asterisksourcejessie(unfixed)end-of-life
asterisksourcestretch1:13.14.1~dfsg-2+deb9u9ELA-1032-1
asterisksourcebuster1:16.28.0~dfsg-0+deb10u4DLA-3696-1
asterisksourcebullseye1:16.28.0~dfsg-0+deb11u4DSA-5596-1
asterisksource(unstable)1:20.5.1~dfsg+~cs6.13.40431414-11059032

Notes

https://github.com/asterisk/asterisk/security/advisories/GHSA-8857-hfmw-vg8f
https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5

Search for package or bug name: Reporting problems