Candidate: CVE-2014-4046 PublicDate: 2014-06-17 14:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4046 http://downloads.asterisk.org/pub/security/AST-2014-006.html http://packetstormsecurity.com/files/127088/Asterisk-Project-Security-Advisory-AST-2014-006.html Description: Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_asterisk: upstream: http://downloads.asterisk.org/pub/security/AST-2014-006-11.diff upstream_asterisk: released (1:11.10.2~dfsg-1) lucid_asterisk: ignored (reached end-of-life) precise_asterisk: ignored (reached end-of-life) precise/esm_asterisk: DNE (precise was needed) saucy_asterisk: ignored (reached end-of-life) trusty_asterisk: ignored (reached end-of-life) trusty/esm_asterisk: DNE (trusty was needed) utopic_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) vivid_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) vivid/stable-phone-overlay_asterisk: DNE vivid/ubuntu-core_asterisk: DNE wily_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) xenial_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) yakkety_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) zesty_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) artful_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) bionic_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) cosmic_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) disco_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1) devel_asterisk: not-affected (1:11.11.0~dfsg-2ubuntu1)