[Bug 293361] net/asterisk2{0,2} updates

From: <bugzilla-noreply_at_freebsd.org>
Date: Sun, 22 Feb 2026 21:55:23 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=293361

--- Comment #11 from commit-hook@FreeBSD.org ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=ab05146a6f7ec39a268ac534831bb1fb5dab0dee

commit ab05146a6f7ec39a268ac534831bb1fb5dab0dee
Author:     Marek Zarychta <zarychtam@plan-b.pwste.edu.pl>
AuthorDate: 2026-02-22 21:53:33 +0000
Commit:     Vladimir Druzenko <vvd@FreeBSD.org>
CommitDate: 2026-02-22 21:53:33 +0000

    net/asterisk22: Update 20.18.1 => 20.18.2

    Security Advisories Resolved: 4
    - GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT
      leading to potential XXE Injection.
    - GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources
      ast_debug_tools.conf from /etc/asterisk; potentially leading to
      privilege escalation.
    - GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus
      page echos user supplied values(cookie and query string) without
      sanitization.
    - GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init
      file to world writeable folder; leading to potential privilege
      escalation.

    Changelog:
   
https://downloads.asterisk.org/pub/telephony/asterisk/old-releases/ChangeLog-20.18.2.html

    PR:             293361
    Approved by:    Oleksandr Kryvulia <o.kryvulia@flex-it.com.ua>
    Security:       GHSA-85x7-54wr-vh42
    Security:       GHSA-rvch-3jmx-3jf3
    Security:       GHSA-v6hp-wh3r-cwxh
    Security:       GHSA-xpc6-x892-v83c
    MFH:            2026Q1

 net/asterisk20/Makefile | 2 +-
 net/asterisk20/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.