PublicDate: 2007-12-20 02:46:00 UTC Candidate: CVE-2007-6430 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6430 Description: Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username. Ubuntu-Description: Notes: mdeslaur> This patch may introduce CVE-2008-5558 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457063 https://bugs.launchpad.net/bugs/199118 Priority: medium Discovered-by: Assigned-to: CVSS: upstream_asterisk: released (1.2.26, 1.4.16) dapper_asterisk: ignored (reached end-of-life) edgy_asterisk: needed (reached end-of-life) feisty_asterisk: needed (reached end-of-life) gutsy_asterisk: needed (reached end-of-life) hardy_asterisk: released (1:1.4.16.2~dfsg-1) intrepid_asterisk: released (1:1.4.16.2~dfsg-1) jaunty_asterisk: released (1:1.4.16.2~dfsg-1) karmic_asterisk: released (1:1.4.16.2~dfsg-1) devel_asterisk: released (1:1.4.16.2~dfsg-1)