Asterisk Project Security Advisory – AST-2014-017

Asterisk Project Security Advisory – The CONFBRIDGE dialplan function when executed from an external protocol (for instance AMI), could result in a privilege escalation. Also, the AMI action “ConfbridgeStartRecord” could also be used to execute arbitrary system commands without first checking for system access.

Leave a Reply