Asterisk: Multiple vulnerabilities — GLSA 202101-10

Multiple vulnerabilities have been found in Asterisk, the worst of which could result in a Denial of Service condition.

Affected packages

net-misc/asterisk on all architectures
Affected versions < 13.38.1
Unaffected versions >= 13.38.1

Background

A Modular Open Source PBX System.

Description

Multiple vulnerabilities have been discovered in Asterisk. Please review the security advisories referenced below for details.

Impact

An attacker could cause a possible Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All Asterisk users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-misc/asterisk-13.38.1"
 

References

Release date
January 12, 2021

Latest revision
January 12, 2021: 1

Severity
normal

Exploitable
remote

Bugzilla entries