An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.
{
"binaries": [
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-voicemail"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-voicemail-imapstorage"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-voicemail-odbcstorage"
},
{
"binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1",
"binary_name": "asterisk-vpb"
}
]
}
{
"binaries": [
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-tests"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-imapstorage"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-voicemail-odbcstorage"
},
{
"binary_version": "1:13.18.3~dfsg-1ubuntu4",
"binary_name": "asterisk-vpb"
}
]
}
{
"binaries": [
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-config"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-dahdi"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-dev"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-mobile"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-modules"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-mp3"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-mysql"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-ooh323"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-tests"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-voicemail"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-voicemail-imapstorage"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-voicemail-odbcstorage"
},
{
"binary_version": "1:16.2.1~dfsg-2ubuntu1",
"binary_name": "asterisk-vpb"
}
]
}