Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sofia-sip: Multiple CVEs on 1.12.11 #4582

Open
CamberLoid opened this issue Jun 17, 2023 · 0 comments
Open

sofia-sip: Multiple CVEs on 1.12.11 #4582

CamberLoid opened this issue Jun 17, 2023 · 0 comments
Assignees
Labels
security Topic/issue involves a security issue/fixed

Comments

@CamberLoid
Copy link
Member

CVE IDs

CVE-2023-32307,CVE-2023-22741,CVE-2022-31003,CVE-2022-31002,CVE-2022-31001

Other security advisory IDs

Debian:

Description

Multiple vulnerabilities of sofia-sip were found and fixed recently. They are:

CVE-2023-32307 heap-over-flow and integer-overflow in certain functions. GHSA-rm4c-ccvf-ff9c
CVE-2023-22741 heap-over-flow in stun_parse_attribute. GHSA-8599-x7rq-fr54
CVE-2022-47516 denial of service with a crafted UDP message. GHSA-h94r-c3pv-4564
CVE-2022-31003 Heap-buffer-overflow on sdp_parse. GHSA-79jq-hh82-cv9g
CVE-2022-31002 Out-of-bound read. GHSA-g3x6-p824-x6hm
CVE-2022-31001 Out-of-bound read. GHSA-79jq-hh82-cv9g

Despite upstream flagged them high to critical severity, as we only use it for gnome-calls and related, which has a limited usage in our distribution, these vulnerabilities are considered moderate severity and is subjected to be included in next security survey

Patches

Update to latest (v1.13.15)

PoC(s)

Included in above advisories.

@CamberLoid CamberLoid added the security Topic/issue involves a security issue/fixed label Jun 17, 2023
@CamberLoid CamberLoid changed the title sofia-sip: Multiple CVEs on current version sofia-sip: Multiple CVEs on1.12.11 Jun 17, 2023
@CamberLoid CamberLoid changed the title sofia-sip: Multiple CVEs on1.12.11 sofia-sip: Multiple CVEs on 1.12.11 Jun 17, 2023
@CamberLoid CamberLoid self-assigned this Jun 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed
Projects
None yet
Development

No branches or pull requests

1 participant