In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan application. The application uses the caller-id name and number as part of a built string passed to the OS shell for interpretation and execution. Since the caller-id name and number can come from an untrusted source, a crafted caller-id name or number allows an arbitrary shell command injection.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "13.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.5.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.10.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.10.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.11.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.12"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.12.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.13.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.14.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.14.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.14.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.14.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.15.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.15.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.15.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.15.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.15.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.16.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.16.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.16.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.17.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.17.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.3.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.4.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.4.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "14.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.5.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "14.5.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "14.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "14.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "11.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.7.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.7.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.8.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "11.8.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.8.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.8.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "11.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.9.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.9.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.9.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "11.10.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.10.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.10.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.10.2"
},
{
"introduced": "0"
},
{
"last_affected": "11.11.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.11.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.12.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.12.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.12.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.13.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.13.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.13.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.14.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.14.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.14.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.14.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.14.2"
},
{
"introduced": "0"
},
{
"last_affected": "11.15.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.15.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.15.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.16.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.17.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.17.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.18.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.18.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.19.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.20.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.21.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.21.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.21.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.21.2"
},
{
"introduced": "0"
},
{
"last_affected": "11.22.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.22.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.23.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.23.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.23.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.24.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.24.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.25.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.25.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert1_rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert10"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert11"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert12"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert13"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert14_rc2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert15"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert16"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert4"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert5"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert6"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert7"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert8"
},
{
"introduced": "0"
},
{
"last_affected": "11.6-cert9"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1_rc1"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1_rc2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1_rc3"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert1_rc4"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert2"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert3"
},
{
"introduced": "0"
},
{
"last_affected": "13.13-cert4"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14100.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.01"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.02"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.4.0-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.10.1-rc1"
}
]
}
]