#VU13262 Information disclosure in Asterisk Open Source
Published: June 12, 2018 / Updated: June 12, 2018
Asterisk Open Source
Digium (Linux Support Services)
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error when the system is configured with endpoint-specific access control list (ACL) rules. A remote attacker can send a SIP request to cause the system to return a 403 Forbidden response and disclose the existence of the PJSIP endpoint.