Package: asterisk Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for asterisk.
CVE-2007-6430[0]: | Due to the way database-based registrations ("realtime") | are processed, IP addresses are not checked when the | username is correct and there is no password. An | attacker may impersonate any user using host-based | authentication without a secret, simply by guessing the | username of that user. This is limited in scope to | administrators who have set up the registration database | ("realtime") for authentication and are using only | host-based authentication, not passwords. However, both | the SIP and IAX protocols are affected. If you fix this vulnerability please also include the CVE id in your changelog entry. For further information: [0] http://downloads.digium.com/pub/security/AST-2007-027.html Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.
pgp7vz1hkIhkH.pgp
Description: PGP signature