Deutsch   English   Fran├žais   Italiano  
<FsVf3-4rmp-1@gated-at.bofh.it>

View for Bookmarking (what is this?)
Look up another Usenet article

Path: ...!weretis.net!feeder8.news.weretis.net!usenet.goja.nl.eu.org!aioe.org!news.servidellagleba.it!bofh.it!news.nic.it!robomod
From: Markus Koschany <apo@debian.org>
Newsgroups: linux.debian.announce.security
Subject: [SECURITY] [DSA 5285-1] asterisk security update
Date: Thu, 17 Nov 2022 23:10:01 +0100
Message-ID: <FsVf3-4rmp-1@gated-at.bofh.it>
X-Mailbox-Line: From debian-security-announce-request@lists.debian.org  Thu Nov 17 22:00:12 2022
Old-Return-Path: <apo@seger.debian.org>
X-Amavis-Spam-Status: No, score=-116.705 tagged_above=-10000 required=5.3
	tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIMWL_WL_HIGH=-0.515,
	DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,
	DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5,
	PGPSIGNATURE=-5, RCVD_IN_DNSWL_HI=-5, USER_IN_DKIM_WELCOMELIST=-0.01,
	USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no
Old-Dkim-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org;
	s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date
	:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description:
	In-Reply-To:References; bh=oDhEBPnzOz60amzn3wYSkBrOKbgFgtqPrNcVIkNkh64=; b=U/
	AFDeJ5yDYgS/UEJn44zfN05eBb7NzaCVpMfehF/D68GZUgG0QRop8Mf0IqOYTstBI4b5Eug8xHRX7
	v/axm1MMc7AEbM78TcdCJDGlyFavX3YjdjV7IfxnPyf8+n/fjt5krpz6fXvXWR8swyNM0WXSM2X1h
	9eQpZoD/37cYNI3Bu9ILu3O+7paUpzo/xKThjaey5ch+WhkHS0t1q7Tmhz7kpyYUTamzkIESiVbGL
	bKFO6R3ZMjI04GAa+jpcx2nezXoJG11easvzoabdHZGOQIo9zkmq/wt8zxeCxXAq5wAuZLYqDAE+7
	Y8d94lJ6X+8bygbXJ2h/Ic7+mrU3/TgA==;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Debian: PGP check passed for security officers
Priority: urgent
X-Debian: PGP check passed for security officers
Reply-To: debian-security-announce-request@lists.debian.org
X-Mailing-List: <debian-security-announce@lists.debian.org> archive/latest/4185
List-ID: <debian-security-announce.lists.debian.org>
List-URL: <http://lists.debian.org/debian-security-announce/>
List-Archive: https://lists.debian.org/msgid-search/Y3aq4vCMbtS7W3Bm@seger.debian.org
Approved: robomod@news.nic.it
Lines: 60
Organization: linux.* mail to news gateway
Sender: robomod@news.nic.it
X-Original-Date: Thu, 17 Nov 2022 21:42:58 +0000
X-Original-Message-ID: <Y3aq4vCMbtS7W3Bm@seger.debian.org>
Bytes: 5490

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5285-1                   security@debian.org
https://www.debian.org/security/                          Markus Koschany
November 17, 2022                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : asterisk
CVE ID         : CVE-2021-37706 CVE-2021-43299 CVE-2021-43300 CVE-2021-43301
                 CVE-2021-43302 CVE-2021-43303 CVE-2021-43804 CVE-2021-43845
                 CVE-2021-46837 CVE-2022-21722 CVE-2022-21723 CVE-2022-23608
                 CVE-2022-24763 CVE-2022-24764 CVE-2022-24786 CVE-2022-24792
                 CVE-2022-24793 CVE-2022-26498 CVE-2022-26499 CVE-2022-26651
Debian Bug     : 1014998 1018073 1014976

Multiple security vulnerabilities have been found in Asterisk, an Open Source
Private Branch Exchange. Buffer overflows and other programming errors could be
exploited for information disclosure or the execution of arbitrary code.

Special care should be taken when upgrading to this new upstream release.
Some configuration files and options have changed in order to remedy
certain security vulnerabilities. Most notably the pjsip TLS listener only
accepts TLSv1.3 connections in the default configuration now. This can be
reverted by adding method=tlsv1_2 to the transport in pjsip.conf. See also
https://issues.asterisk.org/jira/browse/ASTERISK-29017.

For the stable distribution (bullseye), these problems have been fixed in
version 1:16.28.0~dfsg-0+deb11u1.

We recommend that you upgrade your asterisk packages.

For the detailed security status of asterisk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/asterisk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmN2qoFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7
UeR0pQ/+Kr+FWFeFyrkFTyVv5BGBJug+EvZzzC2JZoI/TNsiAWQi/BZTQJ0pmdZr
EHokqN7Z35EqZW6sj5aypdK7bOv4N+uv6P59xROk1KjEEG6XttGJ2BUvffWYWEXo
k6+ou/yfAxU72Ufd1eOcMtjyGeN0CljmemIJ5Cywpnaw8YArP+VzRK2NEth0gCmJ
TAfSvIPFaS7jB6fEg8KESOpmvtlqEJUh5sjP2t+OOEc3AoNBBuj4ZC44SQ1nif6k
jEbmLFnJYQF8dP+IasZ3SY80N+BeuGiylZQ6w1ZvuYuUAK3jhHQ3CJvTQ4sEqNQV
Zva6t0kHOEKVxKg412oEpQ0ihR+EBF/lnECu7iR2HTKk8xteNwio5qeeW/joTAJx
OTYlHTtERTZIiaHdmV3nmGYgrTLeDHClilCnJrQuyXF+LVHjxBWDh7WS83zSrdIH
gNP0eZ5UEjrpomf1yKqHVUsji63eSWACdFVXJLACMwpuevq8qgV6zASD+VuUd36r
foEOKVj+FIHehWSef9pP48Na8bOn0EDVqtZEPOjE6o8Y8PjgSf7BSNogppZncldw
VREox9NsxGM9hSVh3lVBWL8lT76HQVzXjfXXXoIEFDiGokNRV/dNTuhhb/mh0zxr
VTKBboC6ijQVCdVQ7UdGFnoVXOWW2gy8sdam40ELBUCGDD5XI7A=
=eajm
-----END PGP SIGNATURE-----