Asterisk: Multiple vulnerabilities Multiple vulnerabilities in Asterisk might allow remote attackers to cause a Denial of Service condition, or conduct other attacks. asterisk 2010-06-04 2010-06-04 281107 283624 284892 295270 remote 1.2.37 1.2.37

Asterisk is an open source telephony engine and toolkit.

Multiple vulnerabilities have been reported in Asterisk:

A remote attacker could exploit these vulnerabilities by sending a specially crafted package, possibly causing a Denial of Service condition, or resulting in information disclosure.

There is no known workaround at this time.

All Asterisk users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.2.37"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since January 5, 2010. It is likely that your system is already no longer affected by this issue.

CVE-2009-2726 CVE-2009-2346 CVE-2009-4055 CVE-2009-3727 CVE-2008-7220 craig a3li a3li