[Bug 293361] net/asterisk2{0,2} updates

From: <bugzilla-noreply_at_freebsd.org>
Date: Sun, 22 Feb 2026 09:27:21 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=293361

            Bug ID: 293361
           Summary: net/asterisk2{0,2} updates
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs@FreeBSD.org
          Reporter: zarychtam@plan-b.pwste.edu.pl

Created attachment 268264
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=268264&action=edit
0001-net-asterisk20-Update-20.18.1-20.18.2.patch

Those are simple port update patches. 
A few security advisories have been resolved here, so we should update the
quarterly branch as well.  


Security Advisories Resolved: 4
- GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to
potential XXE Injection
- GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources
ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege
escalation
- GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus page
echos user supplied values(cookie and query string) without sanitization
- GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init file to
world writeable folder; leading to potential privilege escalation

-- 
You are receiving this mail because:
You are the assignee for the bug.