CVE-2007-6171

Publication date 30 November 2007

Last updated 17 July 2025


Ubuntu priority

Description

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Read the notes from the security team

Status

Package Ubuntu Release Status
asterisk 8.10 intrepid
Fixed 1:1.4.15~dfsg-1
8.04 LTS hardy
Fixed 1:1.4.15~dfsg-1
7.10 gutsy Ignored end of life, was needed
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


fujitsu

Only affects 1.4.x, x<15.


Access our resources on patching vulnerabilities