Date: Tue, 22 Dec 2020 22:44:24 +0000 (UTC) From: Guido Falsi <madpilot@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r558949 - head/security/vuxml Message-ID: <202012222244.0BMMiOP4041562@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: madpilot Date: Tue Dec 22 22:44:24 2020 New Revision: 558949 URL: https://svnweb.freebsd.org/changeset/ports/558949 Log: Document new asterisk vulnerabilities. Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Tue Dec 22 21:45:18 2020 (r558948) +++ head/security/vuxml/vuln.xml Tue Dec 22 22:44:24 2020 (r558949) @@ -58,6 +58,45 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="6adf6ce0-44a6-11eb-95b7-001999f8d30b"> + <topic>asterisk -- Remote crash in res_pjsip_diversion</topic> + <affects> + <package> + <name>asterisk13</name> + <range><lt>13.38.1</lt></range> + </package> + <package> + <name>asterisk16</name> + <range><lt>16.15.1</lt></range> + </package> + <package> + <name>asterisk18</name> + <range><lt>18.1.1</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The Asterisk project reports:</p> + <blockquote cite="https://www.asterisk.org/downloads/security-advisories"> + <p>AST-2020-003: A crash can occur in Asterisk when a SIP + message is received that has a History-Info header, which + contains a tel-uri.</p> + <p>AST-2020-004: A crash can occur in Asterisk when a SIP + 181 response is received that has a Diversion header, + which contains a tel-uri.</p> + </blockquote> + </body> + </description> + <references> + <url>https://downloads.asterisk.org/pub/security/AST-2020-003.html</url> + <url>https://downloads.asterisk.org/pub/security/AST-2020-004.html</url> + </references> + <dates> + <discovery>2020-12-02</discovery> + <entry>2020-12-22</entry> + </dates> + </vuln> + <vuln vid="eb2845c4-43ce-11eb-aba5-00a09858faf5"> <topic>postsrsd -- Denial of service vulnerability</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202012222244.0BMMiOP4041562>