Asterisk: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201110-21 / Asterisk |
| Release Date |
October 24, 2011 |
| Latest Revision |
October 24, 2011: 1 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/asterisk |
<
1.8.7.1 |
>=
1.8.7.1,
revision >=
1.6.2.18.2 |
All supported architectures
|
Related bugreports:
#352059, #355967, #359767, #364887, #372793, #373409, #387453
Synopsis
Multiple vulnerabilities in Asterisk might allow unauthenticated
remote attackers to execute arbitrary code.
2.
Impact Information
Background
Asterisk is an open source telephony engine and toolkit.
Description
Multiple vulnerabilities have been discovered in Asterisk. Please review
the CVE identifiers referenced below for details.
Impact
An unauthenticated remote attacker may execute code with the privileges
of the Asterisk process or cause a Denial of Service.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All asterisk 1.6.x users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.6.2.18.2"
|
All asterisk 1.8.x users should upgrade to the latest version:
Code Listing 3.2: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.8.7.1"
|
4.
References
|