Information disclosure in Asterisk Open Source and Certified Asterisk - CVE-2018-12227
Published: November 12, 2018
Vulnerability identifier: #VU15804
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12227
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to application responds with different error codes depending on presence of ACL rules for SIP requests. A remote attacker can identify presence of ACL rules.
Affected software
Asterisk Open Source
Certified Asterisk
Gentoo Linux
asterisk (Debian package)
Certified Asterisk
Gentoo Linux
asterisk (Debian package)
How to mitigate CVE-2018-12227
Install updates from vendor's website.
Asterisk Open Source - addressed in versions 13.21.1, 14.7.7, 15.4.1
Certified Asterisk - addressed in versions 13.18-cert4, 13.21-cert2
asterisk (Debian package) - update to 1:13.14.1~dfsg-2+deb9u4
Certified Asterisk - addressed in versions 13.18-cert4, 13.21-cert2
asterisk (Debian package) - update to 1:13.14.1~dfsg-2+deb9u4