Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-1390

Опубликовано: 24 мар. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 9.3

Описание

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

1:1.4.21.2~dfsg-3ubuntu2
edgy

not-affected

feisty

not-affected

gutsy

ignored

end of life, was needed
hardy

released

1:1.4.17~dfsg-2ubuntu1.1
intrepid

not-affected

1:1.4.21.2~dfsg-1ubuntu3
jaunty

not-affected

1:1.4.21.2~dfsg-3ubuntu2
upstream

not-affected

1.4.19-rc3

Показывать по

9.3 Critical

CVSS2

Связанные уязвимости

nvd
почти 18 лет назад

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

debian
почти 18 лет назад

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.1 ...

github
почти 4 года назад

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

9.3 Critical

CVSS2