An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
{ "binaries": [ { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-config" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-dahdi" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-dev" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-mobile" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-modules" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-mp3" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-mysql" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-ooh323" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-voicemail" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-voicemail-imapstorage" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-voicemail-odbcstorage" }, { "binary_version": "1:13.1.0~dfsg-1.1ubuntu4.1+esm1", "binary_name": "asterisk-vpb" } ] }
{ "binaries": [ { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-config" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-dahdi" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-dev" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-mobile" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-modules" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-mp3" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-mysql" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-ooh323" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-tests" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-voicemail" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-voicemail-imapstorage" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-voicemail-odbcstorage" }, { "binary_version": "1:13.18.3~dfsg-1ubuntu4", "binary_name": "asterisk-vpb" } ] }
{ "binaries": [ { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-config" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-dahdi" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-dev" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-mobile" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-modules" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-mp3" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-mysql" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-ooh323" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-tests" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-voicemail" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-voicemail-imapstorage" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-voicemail-odbcstorage" }, { "binary_version": "1:16.2.1~dfsg-2ubuntu1", "binary_name": "asterisk-vpb" } ] }
{ "binaries": [ { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-config" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-dahdi" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-dev" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-mobile" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-modules" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-mp3" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-mysql" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-ooh323" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-tests" }, { "binary_version": "1:18.10.0~dfsg+~cs6.10.40431411-2", "binary_name": "asterisk-vpb" } ] }
{ "binaries": [ { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-config" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-dahdi" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-dev" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-mobile" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-modules" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-mp3" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-mysql" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-ooh323" }, { "binary_version": "1:20.6.0~dfsg+~cs6.13.40431414-2build5", "binary_name": "asterisk-tests" } ] }
{ "binaries": [ { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-config" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-dahdi" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-dev" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-mobile" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-modules" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-mp3" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-mysql" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-ooh323" }, { "binary_version": "1:22.2.0~dfsg+~cs6.15.60671435-2", "binary_name": "asterisk-tests" } ] }