Alpine: asterisk: security update to 20.8.1-r0

medium Tenable Cloud Security Plugin ID 408417

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL
unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is
fixed in 18.23.1, 20.8.1, and 21.3.1. (CVE-2024-35190)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-35190

Plugin Details

Severity: Medium

ID: 408417

Version: Revision 1.8

Type: Local

Published: 5/22/2024

Updated: 8/28/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-35190

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/17/2024

Reference Information

CVE: CVE-2024-35190