net-misc/asterisk: CVE-2018-12227, CVE-2018-17281
authorTony Vroon <chainsaw@gentoo.org>
Wed, 17 Oct 2018 08:26:36 +0000 (09:26 +0100)
committerTony Vroon <chainsaw@gentoo.org>
Wed, 17 Oct 2018 08:29:28 +0000 (09:29 +0100)
commit8979cd86bc10fb98bb70fc9a710d17912af73982
tree94730ce52dbfec2ec9460768c3e9c6b51f2d4a34
parent3a2ebeaae45dcfc7a62deb77e9d8f28d7d29b9dd
net-misc/asterisk: CVE-2018-12227, CVE-2018-17281

Version bump to 13.23.1 to address 2 security vulnerabilities.

CVE-2018-12227: PJSIP information disclosure
SIP requests blocked by ACL respond 403 for an endpoint that
exists and 401 for an endpoint that does not, allowing an
attacker to identify valid accounts.

CVE-2018-17281: HTTP websocket stack overflow
An attacker can exhaust available stack space and crash the
running Asterisk instance by sending a specially crafted HTTP
request to res_http_websocket.so

Bug: https://bugs.gentoo.org/668848
Signed-Off-By: Tony Vroon <chainsaw@gentoo.org>
Package-Manager: Portage-2.3.49, Repoman-2.3.11
net-misc/asterisk/Manifest
net-misc/asterisk/asterisk-13.23.1.ebuild [new file with mode: 0644]