Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2011-01-20T18:00:00
Updated: 2024-08-06T21:58:24.451Z
Reserved: 2011-01-19T00:00:00
Link: CVE-2011-0495
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-01-20T19:00:08.600
Modified: 2024-11-21T01:24:08.320
Link: CVE-2011-0495
Redhat
No data.