Several vulnerabilites are fixed in Asterisk, an Open Source PBX and telephony toolkit. CVE-2019-13161 . Package : asterisk Version : 1:11.13.1~dfsg-2+deb8u7 CVE ID : CVE-2019-13161 CVE-2019-18610 CVE-2019-18790 Several vulnerabilites are fixed in Asterisk, an Open Source PBX and telephony toolkit. CVE-2019-13161 An attacker was able to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. CVE-2019-18610 Remote authenticated Asterisk Manager Interface (AMI) users without system authorization could execute arbitrary system commands. CVE-2019-18790 A SIP call hijacking vulnerability. For Debian 8 "Jessie", these problems have been fixed in version 1:11.13.1~dfsg-2+deb8u7. We recommend that you upgrade your asterisk packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS patches address numerous vulnerabilities in the Asterisk telephony framework, urging users to implement the update.. Debian Security Updates, Asterisk Telephony Security, Open Source PBX, Remote Command Execution Issues, System Integrity. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.