Asterisk: Multiple vulnerabilities Multiple vulnerabilities have been found in Asterisk, the worst of which allows remote execution of arbitrary shell commands. asterisk 2017-10-29 2017-10-29 629682 629692 633856 remote 11.25.3 11.25.3

A Modular Open Source PBX System.

Multiple vulnerabilities have been discovered in Asterisk. Please review the referenced CVE identifiers for details.

A remote attacker could execute arbitrary code, cause a denial of service condition, or cause an unauthorized data disclosure by enticing a user to run malicious code.

There is no known workaround at this time.

All Asterisk users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/asterisk-13.17.2"
CVE-2017-14098 CVE-2017-14099 CVE-2017-14100 CVE-2017-14603 jmbailey jmbailey