[asterisk-bugs] [Asterisk 0017908]: [patch] MeetMe PIN handling broken
Asterisk Bug Tracker
noreply at bugs.digium.com
Tue Aug 31 18:14:08 CDT 2010
A NOTE has been added to this issue.
======================================================================
https://issues.asterisk.org/view.php?id=17908
======================================================================
Reported By: kuj
Assigned To:
======================================================================
Project: Asterisk
Issue ID: 17908
Category: Applications/app_meetme
Reproducibility: always
Severity: minor
Priority: normal
Status: ready for testing
Asterisk Version: 1.4.35
JIRA: SWP-2123
Regression: No
Reviewboard Link:
SVN Branch (only for SVN checkouts, not tarball releases): N/A
SVN Revision (number only!):
Request Review:
======================================================================
Date Submitted: 2010-08-24 20:35 CDT
Last Modified: 2010-08-31 18:14 CDT
======================================================================
Summary: [patch] MeetMe PIN handling broken
Description:
The handling of PINs in app_meetme is broken. Users are prompted for PINs
that don't exist, and regular users can gain conference admin privileges
without a conference's admin PIN.
======================================================================
Relationships ID Summary
----------------------------------------------------------------------
related to 0015704 [patch] MeetMe privilege escalation in ...
======================================================================
----------------------------------------------------------------------
(0126515) kuj (reporter) - 2010-08-31 18:14
https://issues.asterisk.org/view.php?id=17908#c126515
----------------------------------------------------------------------
Patch for 1.8.0-beta4 is analogous to posted patch, except it uses
ast_test_flag64() instead of ast_test_flag().
Issue History
Date Modified Username Field Change
======================================================================
2010-08-31 18:14 kuj Note Added: 0126515
======================================================================
More information about the asterisk-bugs
mailing list