Asterisk: Multiple vulnerabilities — GLSA 201811-11

Multiple vulnerabilities have been found in Asterisk, the worst of which could result in a Denial of Service condition.

Affected Packages

net-misc/asterisk on all architectures
Affected versions < 13.23.1
Unaffected versions >= 13.23.1

Background

A Modular Open Source PBX System.

Description

Multiple vulnerabilities have been discovered in Asterisk. Please review the referenced CVE identifiers for details.

Impact

A remote attacker could cause a Denial of Service condition or conduct information gathering.

Workaround

There is no known workaround at this time.

Resolution

All Asterisk users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-misc/asterisk-13.23.1"
 

References

Release Date
November 24, 2018

Latest Revision
November 24, 2018: 1

Severity
normal

Exploitable
remote

Bugzilla entries