FreeBSD : asterisk -- Multiple Vulnerabilities (bfe9c75e-5028-11e0-b2d2-00215c6a37bb)

high Nessus Plugin ID 52698

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The Asterisk Development Team reports :

The releases of Asterisk 1.6.1.23, 1.6.2.17.1, and 1.8.3.1 resolve two issues :

- Resource exhaustion in Asterisk Manager Interface (AST-2011-003)

- Remote crash vulnerability in TCP/TLS server (AST-2011-004)

The issues and resolutions are described in the AST-2011-003 and AST-2011-004 security advisories.

Solution

Update the affected packages.

See Also

http://downloads.asterisk.org/pub/security/AST-2011-003.html

http://downloads.asterisk.org/pub/security/AST-2011-004.html

http://www.nessus.org/u?518a9489

Plugin Details

Severity: High

ID: 52698

File Name: freebsd_pkg_bfe9c75e502811e0b2d200215c6a37bb.nasl

Version: 1.10

Type: local

Published: 3/17/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:asterisk16, p-cpe:/a:freebsd:freebsd:asterisk18, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 3/16/2011

Vulnerability Publication Date: 3/1/2011