Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 50 articles for you...
197

Debian 11: DLA-4206-1 critical: asterisk authentication issue

Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4206-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://https://www.debian.org/lts/security/ Markus Koschany June 02, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : asterisk Version : 1:16.28.0~dfsg-0+deb11u7 CVE ID : CVE-2025-47779 CVE-2025-47780 Debian Bug : 1106528 1106530 Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779 SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An authenticated attacker can spoof any user identity to send spam messages to the user with their authorization token. Abuse of this security issue allows authenticated attackers to send fake chat messages that can be spoofed to appear to come from trusted entities. CVE-2025-47780 Trying to disallow shell commands to be run via the Asterisk CLI by configuring cli_permissions.conf (e.g. with the config line deny=!*) does not work which could lead to a security risk. A new asterisk.conf option 'disable_remote_console_shell' has been added that, when set, will prevent remote consoles from executing shell commands using the '!' prefix. For Debian 11 bullseye, these problems have been fixed in version 1:16.28.0~dfsg-0+deb11u7. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:https://wiki.debian.org/LTS . Recent findings highlight two severe flaws in Asterisk for Debian, manifesting via inadequate authentication and the risk of remote command execution.. asterisk security, Debian updates, security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 02, 2025 Critical Debian LTS
197

Debian 11: DLA-4042-1 critical: asterisk CVE-2024-53566 path traversal

An issue has been found in asterisk, an Open Source Private Branch Exchange. CVE-2024-53566 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4042-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Daniel Leidert February 06, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : asterisk Version : 1:16.28.0~dfsg-0+deb11u6 CVE ID : CVE-2024-53566 Debian Bug : An issue has been found in asterisk, an Open Source Private Branch Exchange. CVE-2024-53566 It is possible to access files outside the configuration directory via AMI and path traversal even when live_dangerously is not enabled. For Debian 11 bullseye, this problem has been fixed in version 1:16.28.0~dfsg-0+deb11u6. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-4042-2 addresses the security vulnerability in asterisk related to CVE-2024-53567, which impacts file permissions.. Debian Security, asterisk update, path traversal attack, private branch exchange. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 06, 2025 Critical Debian LTS
197

Debian 11 bullseye DLA-3925-1 critical: asterisk privilege escalation

Two issues have been found in asterisk, an Open Source Private Branch Exchange. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3925-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz October 20, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : asterisk Version : 1:16.28.0~dfsg-0+deb11u5 CVE ID : CVE-2024-42365 CVE-2024-42491 Two issues have been found in asterisk, an Open Source Private Branch Exchange. CVE-2024-42365 Due to a privilege escalation, remote code execution and/or blind server-side request forgery with arbitrary protocol are possible. CVE-2024-42491 Due to bad handling of malformed Contact or Record-Route URI in an incoming SIP request, Asterisk might crash when res_resolver_unbound is used. Thanks to Niels Galjaard, a minor privilege escalation has been fixed. More information about ths can be found at: https://alioth-lists.debian.net/pipermail/pkg-voip-maintainers/2024-July/038664.html For Debian 11 bullseye, these problems have been fixed in version 1:16.28.0~dfsg-0+deb11u5. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS patches targeting vulnerability exploitation and unauthorized access flaws in OpenSSH. Update now for improved protection.. Debian Updates, Asterisk Security, Remote Code Execution, Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 20, 2024 Critical Debian LTS
87

Debian Asterisk DSA-5596-1 critical: DoS and memory corruption attacks

Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2023-37457 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5596-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany January 04, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : asterisk CVE ID : CVE-2023-37457 CVE-2023-38703 CVE-2023-49294 CVE-2023-49786 Debian Bug : 1059303 1059032 1059033 Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2023-37457 The 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. CVE-2023-38703 PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level transport is not synchronized with its lower level transport that may introduce a use-after-free issue. This vulnerability affects applications that have SRTP capability (`PJMEDIA_HAS_SRTP` is set) and use underlying media transport other than UDP. This vulnerability’s impact may range from unexpected application termination to control flow hijack/memory corruption. CVE-2023-49294 It is possible to read any arbitrary file even when the`live_dangerously` option is not enabled. CVE-2023-49786 Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. For the oldstable distribution (bullseye), these problems have been fixed in version 1:16.28.0~dfsg-0+deb11u4. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Numerous vulnerabilities in Asterisk require immediate updates for Debian users to preserve system stability and security.. Debian Asterisk Security Update, Vulnerability Management, DoS Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 04, 2024 Critical Debian
197

Debian 10 Asterisk DLA-3696-1 Moderate: Memory Corruption DoS Issues

Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2023-37457 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3696-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany December 28, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : asterisk Version : 1:16.28.0~dfsg-0+deb10u4 CVE ID : CVE-2023-37457 CVE-2023-38703 CVE-2023-49294 CVE-2023-49786 Debian Bug : 1059303 1059032 1059033 Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2023-37457 The 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. CVE-2023-38703 PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level transport is not synchronized with its lower level transport that may introduce a use-after-free issue. This vulnerability affects applications that have SRTP capability (`PJMEDIA_HAS_SRTP` is set) and use underlying media transport other than UDP. This vulnerability’s impact may range from unexpected application termination to control flow hijack/memory corruption. CVE-2023-49294 It is possible to read any arbitraryfile even when the `live_dangerously` option is not enabled. CVE-2023-49786 Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. For Debian 10 buster, these problems have been fixed in version 1:16.28.0~dfsg-0+deb10u4. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Boost your Asterisk setups on Debian 10 by upgrading to the newest packages to address security vulnerabilities. Discover additional details here.. Debian LTS,Asterisk Security,Memory Corruption,Buffer Overflow,DoS. . LinuxSecurity.com Team

Calendar%202 Dec 28, 2023 Debian LTS
87

Debian: DSA-5438-1 High: Asterisk Buffer Overflow in PJSIP DNS Resolver

A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5438-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany June 22, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : asterisk CVE ID : CVE-2023-27585 Debian Bug : 1036697 A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead. For the oldstable distribution (bullseye), this problem has been fixed in version 1:16.28.0~dfsg-0+deb11u3. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical asterisk patch for Debian rectifies stack overflow vulnerability in PJSIP domain name resolver. Suggested enhancements outlined.. Debian Security,Asterisk Update,DNS Resolver Security,BufferOverflow Risk,Open Source Protection. . LinuxSecurity.com Team

Calendar%202 Jun 22, 2023 Debian
197

Debian 10: DLA-3394-1 Critical: Asterisk Buffer Overflow Impacting PJSIP

A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue . -------------------------------------------------------------------------Debian LTS Advisory DLA-3394-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany April 19, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : asterisk Version : 1:16.28.0~dfsg-0+deb10u3 CVE ID : CVE-2023-27585 A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead. For Debian 10 buster, this problem has been fixed in version 1:16.28.0~dfsg-0+deb10u3. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Announcement DLA-3394-1 addresses a critical buffer overflow vulnerability in Asterisk that affects DNS handling. Immediate update recommended.. Debian LTS,Asterisk,Security Update,Buffer Overflow,PJSIP. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 18, 2023 Critical Debian LTS
87

Debian DSA-5358-1 Asterisk Moderate Threat: Denial Of Service

Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. Buffer overflows and other programming errors could be exploited for launching a denial of service attack or the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5358-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany February 23, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : asterisk CVE ID : CVE-2022-23537 CVE-2022-23547 CVE-2022-31031 CVE-2022-37325 CVE-2022-39244 CVE-2022-39269 CVE-2022-42705 CVE-2022-42706 Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. Buffer overflows and other programming errorscould be exploited for launching a denial of service attack or the execution of arbitrary code. For the stable distribution (bullseye), these problems have been fixed in version 1:16.28.0~dfsg-0+deb11u2. We recommend that you upgrade your asterisk packages. For the detailed security status of asterisk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/asterisk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Alert issued on various vulnerabilities in Asterisk impacting Debian platforms. Urgent patches advised to mitigate potential threats.. Debian Security,Asterisk Update,Denial Of Service,Buffer Overflow,Software Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 23, 2023 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200