GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Oct 24, 2011 7:26 pm Post subject: [ GLSA 201110-21 ] Asterisk: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: Asterisk: Multiple vulnerabilities (GLSA 201110-21)
Severity: high
Exploitable: remote
Date: October 24, 2011
Bug(s): #352059, #355967, #359767, #364887, #372793, #373409, #387453
ID: 201110-21
Synopsis
Multiple vulnerabilities in Asterisk might allow unauthenticated
remote attackers to execute arbitrary code.
Background
Asterisk is an open source telephony engine and toolkit.
Affected Packages
Package: net-misc/asterisk
Vulnerable: < 1.8.7.1
Unaffected: >= 1.8.7.1
Unaffected: >= 1.6.2.18.2 < 1.6.2.18.3
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Asterisk. Please review
the CVE identifiers referenced below for details.
Impact
An unauthenticated remote attacker may execute code with the privileges
of the Asterisk process or cause a Denial of Service.
Workaround
There is no known workaround at this time.
Resolution
All asterisk 1.6.x users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.6.2.18.2"
| All asterisk 1.8.x users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.8.7.1"
|
References
CVE-2011-1147
CVE-2011-1174
CVE-2011-1175
CVE-2011-1507
CVE-2011-1599
CVE-2011-2529
CVE-2011-2535
CVE-2011-2536
CVE-2011-2665
CVE-2011-2666
CVE-2011-4063 |
|