[ GLSA 202006-20 ] Asterisk: Root privilege escalation

Aaron Bauman <[email protected]>
Newsgroups gmane.linux.gentoo.announce
Message-ID <20200615155414.GI17996@bubba>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202006-20
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: Asterisk: Root privilege escalation
     Date: June 15, 2020
     Bugs: #602722
       ID: 202006-20

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability was discovered in Asterisk which may allow local
attackers to gain root privileges.

Background
==========

A Modular Open Source PBX System.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  net-misc/asterisk          < 13.32.0-r1            >= 13.32.0-r1 

Description
===========

It was discovered that Gentoo’s Asterisk ebuild does not properly set
permissions on its data directories. This only affects OpenRC systems,
as the flaw was exploitable via the init script.

Impact
======

A local attacker could escalate privileges.

Workaround
==========

Users should ensure the proper permissions are set as discussed in the
referenced bugs. Do not run /etc/init.d/asterisk checkperms.

Resolution
==========

All Asterisk users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=net-misc/asterisk-13.32.0-r1"

References
==========


Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202006-20

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2020 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEEDA48qNrrn8VVVcst4yp5f7HQy3AFAl7nmaYACgkQ4yp5f7HQ
y3BXwQf9FplBNxgD2Y+7vRPTHjL5rUxTDciHFiBLyP0qt4YRqqDjmBHO0G7gs0ay
6K6rY9Fz3W2xBEzOBGIk8i+w6hEeUMAiNIHHYT6L6n7WkN2WOcVcX5LwGpLgjXWl
D/jgA6/mcOCjH5wmYelp2oshr4RnNnyppVvF69jyzLnjBvq09aXwYjp8ufBwcQt9
Qm4esMmM4LNKFSeOlIGRT12xQnsR6Aa9Hqo0JU0Nx8hs9JBS9QyyuJ+qw0FVJ9Qr
+7LsTLe9sGDyplNxqZ1Oid9iioe06PjP2bHa0oNpTXKgbaG/mZWRXv3MQHr81Te9
zOz/bsXKaB77GTEcdQOl2ISJqOGhGA==
=dXMc
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.