[asterisk-bugs] [Asterisk 0017908]: [patch] MeetMe PIN handling broken

Asterisk Bug Tracker noreply at bugs.digium.com
Tue Aug 31 18:14:08 CDT 2010


A NOTE has been added to this issue. 
====================================================================== 
https://issues.asterisk.org/view.php?id=17908 
====================================================================== 
Reported By:                kuj
Assigned To:                
====================================================================== 
Project:                    Asterisk
Issue ID:                   17908
Category:                   Applications/app_meetme
Reproducibility:            always
Severity:                   minor
Priority:                   normal
Status:                     ready for testing
Asterisk Version:           1.4.35 
JIRA:                       SWP-2123 
Regression:                 No 
Reviewboard Link:            
SVN Branch (only for SVN checkouts, not tarball releases): N/A 
SVN Revision (number only!):  
Request Review:              
====================================================================== 
Date Submitted:             2010-08-24 20:35 CDT
Last Modified:              2010-08-31 18:14 CDT
====================================================================== 
Summary:                    [patch] MeetMe PIN handling broken
Description: 
The handling of PINs in app_meetme is broken. Users are prompted for PINs
that don't exist, and regular users can gain conference admin privileges
without a conference's admin PIN.
======================================================================
Relationships       ID      Summary
----------------------------------------------------------------------
related to          0015704 [patch] MeetMe privilege escalation in ...
====================================================================== 

---------------------------------------------------------------------- 
 (0126515) kuj (reporter) - 2010-08-31 18:14
 https://issues.asterisk.org/view.php?id=17908#c126515 
---------------------------------------------------------------------- 
Patch for 1.8.0-beta4 is analogous to posted patch, except it uses
ast_test_flag64() instead of ast_test_flag(). 

Issue History 
Date Modified    Username       Field                    Change               
====================================================================== 
2010-08-31 18:14 kuj            Note Added: 0126515                          
======================================================================




More information about the asterisk-bugs mailing list