CVE-2012-2186

Source
https://cve.org/CVERecord?id=CVE-2012-2186
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-2186.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-2186
Downstream
Withdrawn
2026-01-27T04:11:10.921594Z
Published
2012-08-31T14:55:00Z
Modified
2026-01-27T04:11:10.921594Z
Summary
[none]
Details

Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated users to execute arbitrary commands by leveraging originate privileges and providing an ExternalIVR value in an AMI Originate action.

References

Affected packages