net-misc/asterisk: CVE-2018-12227, CVE-2018-17281
Version bump to 13.23.1 to address 2 security vulnerabilities.
CVE-2018-12227: PJSIP information disclosure
SIP requests blocked by ACL respond 403 for an endpoint that
exists and 401 for an endpoint that does not, allowing an
attacker to identify valid accounts.
CVE-2018-17281: HTTP websocket stack overflow
An attacker can exhaust available stack space and crash the
running Asterisk instance by sending a specially crafted HTTP
request to res_http_websocket.so
Bug: https://bugs.gentoo.org/668848
Signed-Off-By: Tony Vroon <chainsaw@gentoo.org>
Package-Manager: Portage-2.3.49, Repoman-2.3.11