Alpine: multiple asterisk packages: security update to 20.8.1-r0

medium Tenable Cloud Security Plugin ID 423677

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL
unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is
fixed in 18.23.1, 20.8.1, and 21.3.1. (CVE-2024-35190)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-35190

Plugin Details

Severity: Medium

ID: 423677

Version: Revision 1.5

Type: Local

Published: 4/4/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-35190

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/17/2024

Reference Information

CVE: CVE-2024-35190