Summary
The remote host is missing updates announced in
advisory GLSA 200905-01.
Solution
All Asterisk users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-misc/asterisk-1.2.32'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200905-01 http://bugs.gentoo.org/show_bug.cgi?id=218966
http://bugs.gentoo.org/show_bug.cgi?id=224835
http://bugs.gentoo.org/show_bug.cgi?id=232696
http://bugs.gentoo.org/show_bug.cgi?id=232698
http://bugs.gentoo.org/show_bug.cgi?id=237476
http://bugs.gentoo.org/show_bug.cgi?id=250748
http://bugs.gentoo.org/show_bug.cgi?id=254304
Insight
Multiple vulnerabilities have been found in Asterisk allowing for Denial of Service and username disclosure.
Severity
Classification
-
CVE CVE-2008-1897, CVE-2008-2119, CVE-2008-3263, CVE-2008-3264, CVE-2008-3903, CVE-2008-5558, CVE-2009-0041 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities