Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2023.1153 asterisk security update 23 February 2023 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: asterisk Publisher: Debian Operating System: Debian GNU/Linux Resolution: Patch/Upgrade CVE Names: CVE-2022-42705 CVE-2022-39269 CVE-2022-39244 CVE-2022-31031 CVE-2022-23547 CVE-2022-23537 CVE-2022-4270 CVE-2022-3732 Original Bulletin: https://lists.debian.org/debian-lts-announce/2023/02/msg00029.html Comment: CVSS (Max): 9.8 CVE-2022-39244 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVSS Source: NVD Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3335-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany February 22, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : asterisk Version : 1:16.28.0~dfsg-0+deb10u2 CVE ID : CVE-2022-23537 CVE-2022-23547 CVE-2022-31031 CVE-2022-37325 CVE-2022-39244 CVE-2022-39269 CVE-2022-42705 CVE-2022-42706 Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. Buffer overflows and other programming errors could be exploited for launching a denial of service attack or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version 1:16.28.0~dfsg-0+deb10u2. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/asterisk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmP2mPlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeRlOQ/9FKEZF9I+TSp6hkuQUp7V7wLeOvVrGf+f1J48Z64E5AZzJWvIhI1WRU3m IaPuvZC16JXsKYiom1QXog/v9UWtyLGCSxX6medSeTslc5u1u33gXTg+2xU/McyN 1ur35hQCtabCWAbGni2aeCdA+OXBHNsAVQlmpa0tlHx+uGIzxapKJBt7XR9ML42e 8oIOXl0egDEX5ZNXHo4XkGvZ/y8963aDDMJEt9l05SNo9Be+rKZEnPxq5BC8ILUh zlswpebVmQCqc9aZrPVsasY2TN+WG8RFJMYvvPwIs+JFAsFDJCqk9gp4Bvbrq4Ci 80PORsSUOf3iF87J8WgaczO/te9Ze7bAhSvL95Ea5zf/DhIHpIQBytuPtoR5BQGG T9DzIsbdSwp6lWK3cVjqAREYPyPjnYc3JeoC7qs6XdHsduWeMBOTdNrEoiZ88pmr j79EITqvUYUvfucthUXEQtK2z51SmIITVHCStw64awwWLs1Z7z6ibeiMKl14/ags cDVD1MVXEZOZ/GzA4fmv3WMbArKuQtm54Z+0eia7sM+2I1PWBGzZifjVV24LiVV2 G1TXgS3KIKuh5etCqUZ6p0hvNtbjkb5AnVNls8YdrEGn31U6GoJCbgBW12zetcZc WRxj5m1Ak2QJdxe9Mo1AbzyBBiu7ub/Sd0sC5Jp1A3q6kW+9PCk= =eH2F - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBY/bVe8kNZI30y1K9AQj5ChAAgTbvZfjy6i6wk+SORUDH6LCFJIsEJSE8 xxw3u5+zvXftspoHPuGnnTp7dLuGFFBbxqQCpoV9M4Y3T2yZb4HYMRKmfTdkZQtB WkKKg9lH7hLtd1fH2i9fNkF+7tPEHd1kUFIkUy48xvrfCEqYuja9U9NI4nWdyiCo ea4T+fq5QbRRTc2+3T6DGbhtH4OfDfdW1KMorCI4w9Qeoznu9Yron3IrzG0PDthl U0vD/z4MzPnXlEx+38bIeUeZCxcau1DEoQfjicJq7UINdFUOWTCZ9N+pjVqf6Y0l b9J9HB8J+A1Brpv6+SdmdvqW1lB7RNiJwDiWpl33V3iG1LK9KUe6auXWn9zVkFZa TICBqfcIMpmjY8vzrfjlIDG3jUMg5IWNr8AqiknEa9/f6x1ROCAp/g+XfswzmQ6P M5fmoMoN/yh4xqFXNgFUo6ep9bcJ9jXgV7Qjxg1UCX0731xdXdbPxFJtRcBxacwi wA4dQGp4iCyguWgX2A5tqq2KI8Zal5Js/vhONc1SfWdP7mCQKWp3aRBz/t4riHSA T0rHWI1NrHRjMcVlutb3ojjf3DlwqLMdGXmQ00+RzseWvuIiMUW92TWvjv80Dym8 wYub4lU2iwYGR0kOMu65XokJMwoPn5bnd08l4YDe77/wGXeb7w11fl2/FOj3mSc5 fKDcpJwQFQY= =Brau -----END PGP SIGNATURE-----