From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-201406-25.xml | 64 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 64 insertions(+) create mode 100644 glsa-201406-25.xml (limited to 'glsa-201406-25.xml') diff --git a/glsa-201406-25.xml b/glsa-201406-25.xml new file mode 100644 index 00000000..319c6e83 --- /dev/null +++ b/glsa-201406-25.xml @@ -0,0 +1,64 @@ + + + + + + Asterisk: Multiple vulnerabilities + Multiple vulnerabilities have been discovered in Asterisk, the + worst of which could allow privileged users to execute arbitrary system + shell commands. + + asterisk + June 25, 2014 + June 25, 2014: 2 + 513102 + remote + + + 11.10.2 + 1.8.28.2 + 11.10.2 + + + +

Asterisk is an open source telephony engine and toolkit.

+
+ +

Multiple vulnerabilities have been discovered in Asterisk. Please review + the CVE identifiers below for details. +

+
+ +

A remote attacker that gains access to a privileged Asterisk account can + execute arbitrary system shell commands. Furthermore an unprivileged + remote attacker could cause a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Asterisk 11 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/asterisk-11.10.2" + + +

All Asterisk 1.8 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.8.28.2" + + +
+ + CVE-2014-4046 + CVE-2014-4047 + + + BlueKnight + + K_F +
-- cgit v1.2.3-65-gdbad